[Buildroot] [PATCH] libcurl: security bump to version 7.61.0

Peter Korsgaard peter at korsgaard.com
Thu Jul 19 21:34:22 UTC 2018


>>>>> "Baruch" == Baruch Siach <baruch at tkos.co.il> writes:

 > Fixes CVE-2018-0500: curl might overflow a heap based memory buffer when
 > sending data over SMTP and using a reduced read buffer.

 > Drop upstream patch.

 > Add reference to tarball signature key.

 > Drop CRYPTO_lock seed. Removed from configure script since 7.45.

 > Cc: Matt Weber <matthew.weber at rockwellcollins.com>
 > Signed-off-by: Baruch Siach <baruch at tkos.co.il>

Committed to 2018.02.x and 2018.05.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list