From 2402634f5a2142202f2b34e206fbebaf58ca1a3c Mon Sep 17 00:00:00 2001 From: Gustavo Zacarias Date: Wed, 25 Jun 2014 15:41:54 -0300 Subject: [PATCH] gnupg: security bump to version 1.4.17 Fixes CVE-2014-4617: The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence. Signed-off-by: Gustavo Zacarias Signed-off-by: Peter Korsgaard --- package/gnupg/gnupg.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/gnupg/gnupg.mk b/package/gnupg/gnupg.mk index c334ac64b5..4c969673c1 100644 --- a/package/gnupg/gnupg.mk +++ b/package/gnupg/gnupg.mk @@ -4,7 +4,7 @@ # ################################################################################ -GNUPG_VERSION = 1.4.16 +GNUPG_VERSION = 1.4.17 GNUPG_SOURCE = gnupg-$(GNUPG_VERSION).tar.bz2 GNUPG_SITE = ftp://ftp.gnupg.org/gcrypt/gnupg GNUPG_LICENSE = GPLv3+ -- 2.30.2