libcurl: security bump to version 7.61.0
authorBaruch Siach <baruch@tkos.co.il>
Thu, 12 Jul 2018 18:15:57 +0000 (21:15 +0300)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 12 Jul 2018 20:18:54 +0000 (22:18 +0200)
commitbf79731153d2739580954161547225acb60f65e8
treeac046e9ea176745975fcd609403f169d5313c5a9
parent572c7af8dbcc9539ea54724e88b0850ae47d98ee
libcurl: security bump to version 7.61.0

Fixes CVE-2018-0500: curl might overflow a heap based memory buffer when
sending data over SMTP and using a reduced read buffer.

Drop upstream patch.

Add reference to tarball signature key.

Drop CRYPTO_lock seed. Removed from configure script since 7.45.

Cc: Matt Weber <matthew.weber@rockwellcollins.com>
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libcurl/0001-Fix-link-with-ssh2-built-with-a-static-mbedtls.patch [deleted file]
package/libcurl/libcurl.hash
package/libcurl/libcurl.mk