From: "Yann E. MORIN" <yann.morin.1998@free.fr>
To: Waldemar Brodkorb <wbx@openadk.org>
Cc: buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH] package/botan: security update to 3.5.0
Date: Mon, 19 Aug 2024 22:12:02 +0200 [thread overview]
Message-ID: <ZsOnEoUSwBXVlVG5@landeda> (raw)
In-Reply-To: <ZsORVO5sPhPtEjSN@waldemar-brodkorb.de>
Waldemar, All,
On 2024-08-19 20:39 +0200, Waldemar Brodkorb spake thusly:
> See here for complete changelogs:
> https://botan.randombit.net/news.html#version-3-5-0-2024-07-08
> https://botan.randombit.net/news.html#version-3-4-0-2024-04-08
>
> CVE-2024-34702: Fix a DoS caused by excessive name constraints. (GH
>
> CVE-2024-39312: Fix a name constraint processing error, where if
> permitted and excluded rules both applied to a certificate, only the
> permitted rules would be checked.
>
> Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Applied to master, after adding the license hash explanation you later
provided, thanks.
Regards,
Yann E. MORIN.
> ---
> package/botan/botan.hash | 4 ++--
> package/botan/botan.mk | 2 +-
> 2 files changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/package/botan/botan.hash b/package/botan/botan.hash
> index 37e00ea9cc..d948271900 100644
> --- a/package/botan/botan.hash
> +++ b/package/botan/botan.hash
> @@ -1,4 +1,4 @@
> # From https://botan.randombit.net/releases/sha256sums.txt
> -sha256 368f11f426f1205aedb9e9e32368a16535dc11bd60351066e6f6664ec36b85b9 Botan-3.3.0.tar.xz
> +sha256 67e8dae1ca2468d90de4e601c87d5f31ff492b38e8ab8bcbd02ddf7104ed8a9f Botan-3.5.0.tar.xz
> # Locally computed
> -sha256 1833cde7c7cc03296b1ef2ddc178b1cd7fd1c476840f32cf6aedb09ab0bc9004 license.txt
> +sha256 db9168bdccaaea26557094436652577cc9bf43164e8be078d88aef1342fe4fb6 license.txt
> diff --git a/package/botan/botan.mk b/package/botan/botan.mk
> index e0bd258f57..561e7bf702 100644
> --- a/package/botan/botan.mk
> +++ b/package/botan/botan.mk
> @@ -4,7 +4,7 @@
> #
> ################################################################################
>
> -BOTAN_VERSION = 3.3.0
> +BOTAN_VERSION = 3.5.0
> BOTAN_SOURCE = Botan-$(BOTAN_VERSION).tar.xz
> BOTAN_SITE = http://botan.randombit.net/releases
> BOTAN_LICENSE = BSD-2-Clause
> --
> 2.30.2
>
> _______________________________________________
> buildroot mailing list
> buildroot@buildroot.org
> https://lists.buildroot.org/mailman/listinfo/buildroot
--
.-----------------.--------------------.------------------.--------------------.
| Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ |
| +33 561 099 427 `------------.-------: X AGAINST | \e/ There is no |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. |
'------------------------------^-------^------------------^--------------------'
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next prev parent reply other threads:[~2024-08-19 20:12 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-19 18:39 [Buildroot] [PATCH] package/botan: security update to 3.5.0 Waldemar Brodkorb
2024-08-19 18:57 ` Waldemar Brodkorb
2024-08-19 20:12 ` Yann E. MORIN [this message]
2024-09-17 21:08 ` Peter Korsgaard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZsOnEoUSwBXVlVG5@landeda \
--to=yann.morin.1998@free.fr \
--cc=buildroot@buildroot.org \
--cc=wbx@openadk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.