From b17e5352cad1214f10ebed5ad68a9bfbcc280690 Mon Sep 17 00:00:00 2001 From: Baruch Siach Date: Fri, 27 Feb 2015 14:08:12 +0200 Subject: [PATCH] gnupg2: security bump to version 2.0.27 Fixes: CVE-2015-1606: Use after free, resulting from failure to skip invalid packets CVE-2015-1607: memcpy with overlapping ranges, resulting from incorrect bitwise left shifts Signed-off-by: Baruch Siach Signed-off-by: Peter Korsgaard --- package/gnupg2/gnupg2.hash | 4 ++-- package/gnupg2/gnupg2.mk | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package/gnupg2/gnupg2.hash b/package/gnupg2/gnupg2.hash index 62fdaee916..404c40bedd 100644 --- a/package/gnupg2/gnupg2.hash +++ b/package/gnupg2/gnupg2.hash @@ -1,2 +1,2 @@ -# Locally calculated after checking pgp signature -sha256 7758e30dc382ae7a7167ed41b7f936aa50af5ea2d6fccdef663b5b750b65b8e0 gnupg-2.0.26.tar.bz2 +# From http://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000362.html +sha1 d065be185f5bac8ea07b210ab7756e79b83b63d4 gnupg-2.0.27.tar.bz2 diff --git a/package/gnupg2/gnupg2.mk b/package/gnupg2/gnupg2.mk index 2d133aa0d5..aa35c36c5a 100644 --- a/package/gnupg2/gnupg2.mk +++ b/package/gnupg2/gnupg2.mk @@ -4,7 +4,7 @@ # ################################################################################ -GNUPG2_VERSION = 2.0.26 +GNUPG2_VERSION = 2.0.27 GNUPG2_SOURCE = gnupg-$(GNUPG2_VERSION).tar.bz2 GNUPG2_SITE = ftp://ftp.gnupg.org/gcrypt/gnupg GNUPG2_LICENSE = GPLv3+ -- 2.30.2