]> code.ossystems Code Review - openembedded-core.git/commit
curl: fix CVE-2021-22890
authorTrevor Gamblin <trevor.gamblin@windriver.com>
Tue, 1 Jun 2021 15:09:27 +0000 (11:09 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 2 Jun 2021 07:21:14 +0000 (08:21 +0100)
commitb11dc35cce0449623182ecf044c4a49664119b9c
treea9b5b8a3782f651e820bbd03a9f929d7de35e84b
parente3ded54f9fd089382e6304604ca02d2305f16f21
curl: fix CVE-2021-22890

Backport and modify the patch for CVE-2021-22890 from curl 7.76 to make
it apply cleanly on 7.75.

CVE: CVE-2021-22890

Signed-off-by: Trevor Gamblin <trevor.gamblin@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-support/curl/curl/0001-vtls-add-isproxy-argument-to-Curl_ssl_get-addsession.patch [new file with mode: 0644]
meta/recipes-support/curl/curl_7.75.0.bb