summaryrefslogtreecommitdiffstats
path: root/package/libidn/0001-lib-punycode.c-decode_digit-Fix-integer-overflow.patch
Commit message (Collapse)AuthorAgeFilesLines
* libidn: bump to version 1.34Fabrice Fontaine2018-05-011-36/+0
| | | | | | | | | - Remove both patches (already in version) - Remove AUTORECONF = YES (patch removed) - Add hash for license files Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
* libidn: add fix for CVE-2017-14062Baruch Siach2017-09-221-0/+36
Add upstream patch fixing CVE-2017-14062: Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact. This issue also affects libidn. Unfortunately, the patch also triggers reconf of the documentation subdirectory, since lib/punycode.c is listed in GDOC_SRC that is defined in doc/Makefile.am. Add autoreconf to handle that. Signed-off-by: Baruch Siach <baruch@tkos.co.il> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
OpenPOWER on IntegriCloud