package/wolfssl: security bump to version 4.7.0
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sat, 6 Mar 2021 16:14:50 +0000 (17:14 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 6 Mar 2021 19:25:34 +0000 (20:25 +0100)
commit238b5df775ac67f0e43afbbf3f2a5e72be275795
tree34a829512ffe8da569ae80165e3afc4662632bcf
parent308f4428c8d8cbe6ea563b295f590a4c3da23646
package/wolfssl: security bump to version 4.7.0

Fix CVE-2021-3336: DoTls13CertificateVerify in tls13.c in wolfSSL before
4.7.0 does not cease processing for certain anomalous peer behavior
(sending an ED22519, ED448, ECC, or RSA signature without the
corresponding certificate). The client side is affected because
man-in-the-middle attackers can impersonate TLS 1.3 servers.

https://github.com/wolfSSL/wolfssl/releases/tag/v4.7.0-stable

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/wolfssl/wolfssl.hash
package/wolfssl/wolfssl.mk