libidn: security bump to version 1.33
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Fri, 22 Jul 2016 23:38:34 +0000 (20:38 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Sat, 23 Jul 2016 13:06:43 +0000 (15:06 +0200)
Fixes:
CVE-2015-8948 - out-of-bounds read in CLI tool.
CVE-2016-6261 - out-of-bounds stack read in idna_to_ascii_4i.
CVE-2016-6262 - followup fix to CVE-2015-8948.
CVE-2016-6263 - stringprep_utf8_nfkc_normalize reject invalid UTF-8.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/libidn/libidn.hash
package/libidn/libidn.mk

index 20c844e12109c543780a9cb4852b30eea4b9d86a..4658a3e8576ac2b9ff07681cb1460cffd7f9d14a 100644 (file)
@@ -1,2 +1,4 @@
-# From http://lists.nongnu.org/archive/html/help-libidn/2015-08/msg00001.html
-sha1   ddd018611b98af7c67d434aa42d15d39f45129f5        libidn-1.32.tar.gz
+# From http://lists.nongnu.org/archive/html/help-libidn/2016-07/msg00009.html
+sha1   57872fdc665dcc585e16f4ac0bb35374b1103f7e        libidn-1.33.tar.gz
+# Calculated based on the hash above
+sha256 44a7aab635bb721ceef6beecc4d49dfd19478325e1b47f3196f7d2acc4930e19        libidn-1.33.tar.gz
index ab439493553e69a0c4db2079156fa85edcdc2e59..99c9e2cb8021479caab369972bd37b0adf0d67bf 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBIDN_VERSION = 1.32
+LIBIDN_VERSION = 1.33
 LIBIDN_SITE = $(BR2_GNU_MIRROR)/libidn
 LIBIDN_INSTALL_STAGING = YES
 LIBIDN_CONF_ENV = EMACS="no"