package/mongoose: security bump to version 6.17
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Wed, 12 Feb 2020 21:21:34 +0000 (22:21 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 13 Feb 2020 17:08:21 +0000 (18:08 +0100)
- Fix CVE-2019-19307: An integer overflow in parse_mqtt in mongoose.c in
  Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS
  (infinite loop), or possibly cause an out-of-bounds write, by sending
  a crafted MQTT protocol packet.
- Update indentation of hash file (two spaces)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mongoose/mongoose.hash
package/mongoose/mongoose.mk

index d3801316314fd1d0e6220f75602520c28c498be4..c5de11bec2cc259b34dbd687d522f6e6bb23f679 100644 (file)
@@ -1,3 +1,3 @@
 # Locally computed:
-sha256 1f20f2781862560ddf3203dfb0e6fcf248a68bf92aefbeafb9d2a629c4767c02  mongoose-6.16.tar.gz
-sha256 fdc34eeea97327d75c83492abd34f1a3200c53dec04422ecda8071dc60a36d10  LICENSE
+sha256  5bff3cc70bb2248cf87d06a3543f120f3b29b9368d25a7715443cb10612987cc  mongoose-6.17.tar.gz
+sha256  fdc34eeea97327d75c83492abd34f1a3200c53dec04422ecda8071dc60a36d10  LICENSE
index bb40de261e9b5be26098ea979a8efe8853b76bdd..7944f5e534cea976d094bdcf385f0329074f33e0 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-MONGOOSE_VERSION = 6.16
+MONGOOSE_VERSION = 6.17
 MONGOOSE_SITE = $(call github,cesanta,mongoose,$(MONGOOSE_VERSION))
 MONGOOSE_LICENSE = GPL-2.0
 MONGOOSE_LICENSE_FILES = LICENSE