libssh: security bump to version 0.7.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 24 Feb 2016 12:01:43 +0000 (09:01 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 24 Feb 2016 16:36:23 +0000 (17:36 +0100)
Fixes:
CVE-2016-0739 - Bits/bytes confusion resulting in truncated
Difffie-Hellman secret length.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libssh/libssh.hash
package/libssh/libssh.mk

index 49bf6c959fe2d88fc2dea777e1539daf28da8c90..1eef804e5c3a5254440cd0da26b505bb380dd2e7 100644 (file)
@@ -1,4 +1,4 @@
 # from https://red.libssh.org/projects/libssh/files/
-md5    5d7d468937649a6dfc6186edfff083db        libssh-0.7.2.tar.xz
-# Locally calculated after checking signature on uncompressed libssh-0.7.2.tar
-sha256 a32c45b9674141cab4bde84ded7d53e931076c6b0f10b8fd627f3584faebae62  libssh-0.7.2.tar.xz
+md5    05465da8004f3258db946346213209de        libssh-0.7.3.tar.xz
+# Locally calculated after checking signature on uncompressed libssh-0.7.3.tar
+sha256 26ef46be555da21112c01e4b9f5e3abba9194485c8822ab55ba3d6496222af98  libssh-0.7.3.tar.xz
index d425ff0b74bcdb079a0491f5dd9ba0e8508d4e63..29bbf4e9f247b28599a78bbb5ecddb020fe7c601 100644 (file)
@@ -4,9 +4,9 @@
 #
 ################################################################################
 
-LIBSSH_VERSION = 0.7.2
+LIBSSH_VERSION = 0.7.3
 LIBSSH_SOURCE = libssh-$(LIBSSH_VERSION).tar.xz
-LIBSSH_SITE = https://red.libssh.org/attachments/download/177
+LIBSSH_SITE = https://red.libssh.org/attachments/download/195
 LIBSSH_LICENSE = LGPLv2.1
 LIBSSH_LICENSE_FILES = COPYING
 LIBSSH_INSTALL_STAGING = YES