From 0c5beb6501707dd5cb80484562bf2b0cbe2b4423 Mon Sep 17 00:00:00 2001 From: Peter Korsgaard Date: Wed, 21 Dec 2016 08:48:49 +0100 Subject: [PATCH] libcurl: security bump to 7.52.0 Fixes CVE-2016-9586 - printf floating point buffer overflow For details, see: https://curl.haxx.se/docs/adv_20161221A.html Signed-off-by: Peter Korsgaard --- package/libcurl/libcurl.hash | 2 +- package/libcurl/libcurl.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/libcurl/libcurl.hash b/package/libcurl/libcurl.hash index e1283350cc..2b68c6a7b4 100644 --- a/package/libcurl/libcurl.hash +++ b/package/libcurl/libcurl.hash @@ -1,2 +1,2 @@ # Locally calculated after checking pgp signature -sha256 7f8240048907e5030f67be0a6129bc4b333783b9cca1391026d700835a788dde curl-7.51.0.tar.bz2 +sha256 b9a2e18b4785eb75ad84598720e1559e1c53550ea011c0e00becdb94e2df5cc6 curl-7.52.0.tar.bz2 diff --git a/package/libcurl/libcurl.mk b/package/libcurl/libcurl.mk index 197e0b579d..b2a1b241dc 100644 --- a/package/libcurl/libcurl.mk +++ b/package/libcurl/libcurl.mk @@ -4,7 +4,7 @@ # ################################################################################ -LIBCURL_VERSION = 7.51.0 +LIBCURL_VERSION = 7.52.0 LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.bz2 LIBCURL_SITE = https://curl.haxx.se/download LIBCURL_DEPENDENCIES = host-pkgconf \ -- 2.30.2