package/sqlcipher: security bump to version 4.4.2
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Thu, 10 Dec 2020 22:08:53 +0000 (23:08 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Mon, 14 Dec 2020 14:44:02 +0000 (15:44 +0100)
commitf38893f8dd7c9fb13b14cf4fe471eb62d345c5f0
tree1a4fcc30b11c7425d81779f4b7e25b4bb2dcea21
parentfe347897b81c546f82787fdc029bbc88c3731bad
package/sqlcipher: security bump to version 4.4.2

Fix CVE-2020-27207: Zetetic SQLCipher 4.x before 4.4.1 has a
use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in
sqlite3.c. A remote denial of service attack can be performed. For
example, a SQL injection can be used to execute the crafted SQL command
sequence. After that, some unexpected RAM data is read.

https://www.zetetic.net/blog/2020/11/25/sqlcipher-442-release

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/sqlcipher/sqlcipher.hash
package/sqlcipher/sqlcipher.mk