All of lore.kernel.org
 help / color / mirror / Atom feed
From: Waldemar Brodkorb <wbx@openadk.org>
To: Waldemar Brodkorb <wbx@openadk.org>
Cc: buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH] package/botan: security update to 3.5.0
Date: Mon, 19 Aug 2024 20:57:25 +0200	[thread overview]
Message-ID: <ZsOVlbDayeReLjLV@waldemar-brodkorb.de> (raw)
In-Reply-To: <ZsORVO5sPhPtEjSN@waldemar-brodkorb.de>

Hi,

I forgot to mention, the License hash changed because the year was
updated from 2023 to 2024.

Waldemar Brodkorb wrote,

> See here for complete changelogs:
> https://botan.randombit.net/news.html#version-3-5-0-2024-07-08
> https://botan.randombit.net/news.html#version-3-4-0-2024-04-08
> 
> CVE-2024-34702: Fix a DoS caused by excessive name constraints. (GH
> 
> CVE-2024-39312: Fix a name constraint processing error, where if
> permitted and excluded rules both applied to a certificate, only the
> permitted rules would be checked.
> 
> Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
> ---
>  package/botan/botan.hash | 4 ++--
>  package/botan/botan.mk   | 2 +-
>  2 files changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/package/botan/botan.hash b/package/botan/botan.hash
> index 37e00ea9cc..d948271900 100644
> --- a/package/botan/botan.hash
> +++ b/package/botan/botan.hash
> @@ -1,4 +1,4 @@
>  # From https://botan.randombit.net/releases/sha256sums.txt
> -sha256  368f11f426f1205aedb9e9e32368a16535dc11bd60351066e6f6664ec36b85b9  Botan-3.3.0.tar.xz
> +sha256  67e8dae1ca2468d90de4e601c87d5f31ff492b38e8ab8bcbd02ddf7104ed8a9f  Botan-3.5.0.tar.xz
>  # Locally computed
> -sha256  1833cde7c7cc03296b1ef2ddc178b1cd7fd1c476840f32cf6aedb09ab0bc9004  license.txt
> +sha256  db9168bdccaaea26557094436652577cc9bf43164e8be078d88aef1342fe4fb6  license.txt
> diff --git a/package/botan/botan.mk b/package/botan/botan.mk
> index e0bd258f57..561e7bf702 100644
> --- a/package/botan/botan.mk
> +++ b/package/botan/botan.mk
> @@ -4,7 +4,7 @@
>  #
>  ################################################################################
>  
> -BOTAN_VERSION = 3.3.0
> +BOTAN_VERSION = 3.5.0
>  BOTAN_SOURCE = Botan-$(BOTAN_VERSION).tar.xz
>  BOTAN_SITE = http://botan.randombit.net/releases
>  BOTAN_LICENSE = BSD-2-Clause
> -- 
> 2.30.2
> 
> _______________________________________________
> buildroot mailing list
> buildroot@buildroot.org
> https://lists.buildroot.org/mailman/listinfo/buildroot
> 
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2024-08-19 18:57 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-08-19 18:39 [Buildroot] [PATCH] package/botan: security update to 3.5.0 Waldemar Brodkorb
2024-08-19 18:57 ` Waldemar Brodkorb [this message]
2024-08-19 20:12 ` Yann E. MORIN
2024-09-17 21:08 ` Peter Korsgaard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZsOVlbDayeReLjLV@waldemar-brodkorb.de \
    --to=wbx@openadk.org \
    --cc=buildroot@buildroot.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.