gnupg2: security bump to version 2.0.27
authorBaruch Siach <baruch@tkos.co.il>
Fri, 27 Feb 2015 12:08:12 +0000 (14:08 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 27 Feb 2015 12:56:49 +0000 (13:56 +0100)
Fixes:

CVE-2015-1606: Use after free, resulting from failure to skip invalid packets

CVE-2015-1607: memcpy with overlapping ranges, resulting from incorrect
bitwise left shifts

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/gnupg2/gnupg2.hash
package/gnupg2/gnupg2.mk

index 62fdaee916a4a609f671439f2fb172c1c5607aae..404c40bedddd7440ecd8647f02be370ba8632183 100644 (file)
@@ -1,2 +1,2 @@
-# Locally calculated after checking pgp signature
-sha256 7758e30dc382ae7a7167ed41b7f936aa50af5ea2d6fccdef663b5b750b65b8e0        gnupg-2.0.26.tar.bz2
+# From http://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000362.html
+sha1   d065be185f5bac8ea07b210ab7756e79b83b63d4        gnupg-2.0.27.tar.bz2
index 2d133aa0d5b8e40420f3c7c1adeb03693b7c4029..aa35c36c5a4b4cda86165c22e8d02b2cdfd608cc 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-GNUPG2_VERSION = 2.0.26
+GNUPG2_VERSION = 2.0.27
 GNUPG2_SOURCE = gnupg-$(GNUPG2_VERSION).tar.bz2
 GNUPG2_SITE = ftp://ftp.gnupg.org/gcrypt/gnupg
 GNUPG2_LICENSE = GPLv3+