libnss: security bump to version 3.17.1
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Thu, 25 Sep 2014 12:48:04 +0000 (09:48 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 25 Sep 2014 19:41:07 +0000 (21:41 +0200)
Fixes CVE-2014-1568 RSA signature forgery attack.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libnss/libnss.hash [new file with mode: 0644]
package/libnss/libnss.mk

diff --git a/package/libnss/libnss.hash b/package/libnss/libnss.hash
new file mode 100644 (file)
index 0000000..8c9420c
--- /dev/null
@@ -0,0 +1,3 @@
+# From https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_1_RTM/src/
+sha1   32347d8b476efa5c7a4cfa21f8e5a1d0d89942ea        nss-3.17.1.tar.gz
+sha256 0e210afba7cd1e033a08f61fcd1f466639649fc413e72aa050f3d52c19376e5f        nss-3.17.1.tar.gz
index a822726e3aa4a07723e2f39a75ba58f894f489c3..066606fb1820a71aa4e6c4b86ed75290df6b8ebf 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBNSS_VERSION = 3.17
+LIBNSS_VERSION = 3.17.1
 LIBNSS_SOURCE = nss-$(LIBNSS_VERSION).tar.gz
 LIBNSS_SITE = https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_$(subst .,_,$(LIBNSS_VERSION))_RTM/src
 LIBNSS_DISTDIR = dist