[Buildroot] [PATCH] package/gnupg2: security bump to version 2.2.23

Peter Korsgaard peter at korsgaard.com
Sat Sep 5 12:37:18 UTC 2020


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues:
 > CVE-2020-25125: Importing an OpenPGP key having a preference list for AEAD
 > algorithms will lead to an array overflow and thus often to a crash or other
 > undefined behaviour (affected: 2.2.21 / 2.2.22)

 > For more details, see the announcement:
 > https://lists.gnupg.org/pipermail/gnupg-announce/2020q3/000448.html

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2020.08.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list