mbedtls: security bump to version 2.2.1
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 6 Jan 2016 17:14:39 +0000 (14:14 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 8 Jan 2016 19:29:22 +0000 (20:29 +0100)
Fixes:
CVE-2015-7575 - Security Losses from Obsolete and Truncated Transcript
Hashes (SLOTH) vulnerability.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mbedtls/mbedtls.hash
package/mbedtls/mbedtls.mk

index 161dc2be6e3937032e0d8932e33076570b39e8b8..eebbfe85610883d1b19fc4d4a8762874084a5eb3 100644 (file)
@@ -1,2 +1,2 @@
-# From https://tls.mbed.org/tech-updates/releases/mbedtls-2.2.0-2.1.3-1.3.15-and-polarssl.1.2.18-released
-sha256 3c6d3487ab056da94450cf907afc84f026aff7880182baffe137c98e3d00fb55        mbedtls-2.2.0-apache.tgz
+# From https://tls.mbed.org/tech-updates/releases/mbedtls-2.2.1-2.1.4-1.3.16-and-polarssl.1.2.19-released
+sha256 6ddd5ca2e7dfb43d2fd750400856246fc1c98344dabf01b1594eb2f9880ef7ce        mbedtls-2.2.1-apache.tgz
index b98b7f5df21894df6fc8265d6cb472449bed003c..fe166e21f4dbdcceaca3d682c4489bd5d1560caf 100644 (file)
@@ -5,7 +5,7 @@
 ################################################################################
 
 MBEDTLS_SITE = https://tls.mbed.org/code/releases
-MBEDTLS_VERSION = 2.2.0
+MBEDTLS_VERSION = 2.2.1
 MBEDTLS_SOURCE = mbedtls-$(MBEDTLS_VERSION)-apache.tgz
 MBEDTLS_CONF_OPTS = \
        -DENABLE_PROGRAMS=$(if $(BR2_PACKAGE_MBEDTLS_PROGRAMS),ON,OFF) \