[Buildroot] [PATCH] package/libcurl: security bump to version 7.83.1

Peter Korsgaard peter at korsgaard.com
Thu May 12 08:48:25 UTC 2022


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues:
 > - CVE-2022-27778: curl removes wrong file on error
 >   https://curl.se/docs/CVE-2022-27778.html

 > - CVE-2022-27779: cookie for trailing dot TLD
 >   https://curl.se/docs/CVE-2022-27779.html

 > - CVE-2022-27780: percent-encoded path separator in URL host
 >   https://curl.se/docs/CVE-2022-27780.html

 > - CVE-2022-27781: CERTINFO never-ending busy-loop
 >   https://curl.se/docs/CVE-2022-27781.html

 > - CVE-2022-27782: TLS and SSH connection too eager reuse
 >   https://curl.se/docs/CVE-2022-27782.html

 > - CVE-2022-30115: HSTS bypass via trailing dot
 >   https://curl.se/docs/CVE-2022-30115.html

 > Drop now upstreamed 0001-mbedtls-fix-compile-when-h2-enabled.patch

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list