summaryrefslogtreecommitdiffstats
path: root/package
diff options
context:
space:
mode:
authorBernd Kuhls <bernd.kuhls@t-online.de>2016-01-28 21:01:26 +0100
committerPeter Korsgaard <peter@korsgaard.com>2016-01-28 22:29:08 +0100
commit4adae5d2eaa2eda770c1b5873265dfbca908d21f (patch)
tree53c187458b3c5546972d888e52bd13906e5481be /package
parent4651c601852b7f35cdfaad047fc44e3a7059ea7f (diff)
downloadbuildroot-4adae5d2eaa2eda770c1b5873265dfbca908d21f.tar.gz
buildroot-4adae5d2eaa2eda770c1b5873265dfbca908d21f.zip
package/libcurl: security bump version to 7.47.0
Fixes CVE-2016-0754: remote file name path traversal in curl tool for Windows CVE-2016-0755: NTLM credentials not-checked for proxy connection re-use Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package')
-rw-r--r--package/libcurl/libcurl.hash4
-rw-r--r--package/libcurl/libcurl.mk2
2 files changed, 3 insertions, 3 deletions
diff --git a/package/libcurl/libcurl.hash b/package/libcurl/libcurl.hash
index eb5bab1e30..cd35d4cc82 100644
--- a/package/libcurl/libcurl.hash
+++ b/package/libcurl/libcurl.hash
@@ -1,2 +1,2 @@
-# Locally calculated after checking pgp signature
-sha256 b7d726cdd8ed4b6db0fa1b474a3c59ebbbe4dcd4c61ac5e7ade0e0270d3195ad curl-7.46.0.tar.bz2
+# Locally calculated
+sha256 2b096f9387fb9b2be08d17e518c62b6537b1f4d4bb59111d5b4fa0272f383f66 curl-7.47.0.tar.bz2
diff --git a/package/libcurl/libcurl.mk b/package/libcurl/libcurl.mk
index e64014ddc9..db9ef3f1bc 100644
--- a/package/libcurl/libcurl.mk
+++ b/package/libcurl/libcurl.mk
@@ -4,7 +4,7 @@
#
################################################################################
-LIBCURL_VERSION = 7.46.0
+LIBCURL_VERSION = 7.47.0
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.bz2
LIBCURL_SITE = http://curl.haxx.se/download
LIBCURL_DEPENDENCIES = host-pkgconf \
OpenPOWER on IntegriCloud