[Buildroot] [PATCH] libidn: security bump to version 1.33

Thomas Petazzoni thomas.petazzoni at free-electrons.com
Sat Jul 23 13:08:36 UTC 2016


Hello,

On Fri, 22 Jul 2016 20:38:34 -0300, Gustavo Zacarias wrote:
> Fixes:
> CVE-2015-8948 - out-of-bounds read in CLI tool.
> CVE-2016-6261 - out-of-bounds stack read in idna_to_ascii_4i.
> CVE-2016-6262 - followup fix to CVE-2015-8948.
> CVE-2016-6263 - stringprep_utf8_nfkc_normalize reject invalid UTF-8.
> 
> Signed-off-by: Gustavo Zacarias <gustavo at zacarias.com.ar>
> ---
>  package/libidn/libidn.hash | 6 ++++--
>  package/libidn/libidn.mk   | 2 +-
>  2 files changed, 5 insertions(+), 3 deletions(-)

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Free Electrons
Embedded Linux, Kernel and Android engineering
http://free-electrons.com



More information about the buildroot mailing list