[Buildroot] [PATCH] package/gnupg2: security bump to version 2.2.23
Peter Korsgaard
peter at korsgaard.com
Sat Sep 5 12:37:18 UTC 2020
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Fixes the following security issues:
> CVE-2020-25125: Importing an OpenPGP key having a preference list for AEAD
> algorithms will lead to an array overflow and thus often to a crash or other
> undefined behaviour (affected: 2.2.21 / 2.2.22)
> For more details, see the announcement:
> https://lists.gnupg.org/pipermail/gnupg-announce/2020q3/000448.html
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed to 2020.08.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list