]> code.ossystems Code Review - openembedded-core.git/commitdiff
openssl10: Upgrade 1.0.2l -> 1.0.2m
authorStefan Agner <stefan.agner@toradex.com>
Sat, 18 Nov 2017 08:53:54 +0000 (09:53 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 2 Dec 2017 11:24:34 +0000 (11:24 +0000)
Deals with two CVEs:
* bn_sqrx8x_internal carry bug on x86_64 (CVE-2017-3736)
* Malformed X.509 IPAddressFamily could cause OOB read (CVE-2017-3735)

Signed-off-by: Stefan Agner <stefan.agner@toradex.com>
Acked-by: Otavio Salvador <otavio@ossystems.com.br>
Signed-off-by: Ross Burton <ross.burton@intel.com>
33 files changed:
meta/recipes-connectivity/openssl/openssl-1.0.2m/0001-Fix-build-with-clang-using-external-assembler.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/0001-Fix-build-with-clang-using-external-assembler.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/0001-openssl-force-soft-link-to-avoid-rare-race.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/0001-openssl-force-soft-link-to-avoid-rare-race.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/Makefiles-ptest.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/Makefiles-ptest.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/Use-SHA256-not-MD5-as-default-digest.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/Use-SHA256-not-MD5-as-default-digest.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/configure-musl-target.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/configure-musl-target.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/configure-targets.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/configure-targets.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/c_rehash-compat.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/c_rehash-compat.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/ca.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/ca.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/debian-targets.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/debian-targets.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/man-dir.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/man-dir.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/man-section.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/man-section.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/no-rpath.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/no-rpath.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/no-symbolic.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/no-symbolic.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/pic.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/pic.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian/version-script.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian/version-script.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian1.0.2/block_digicert_malaysia.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian1.0.2/block_digicert_malaysia.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian1.0.2/block_diginotar.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian1.0.2/block_diginotar.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian1.0.2/soname.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian1.0.2/soname.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/debian1.0.2/version-script.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/debian1.0.2/version-script.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/engines-install-in-libdir-ssl.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/engines-install-in-libdir-ssl.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/find.pl [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/find.pl with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/oe-ldflags.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/oe-ldflags.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/openssl-1.0.2a-x32-asm.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/openssl-1.0.2a-x32-asm.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/openssl-c_rehash.sh [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/openssl-c_rehash.sh with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/openssl-fix-des.pod-error.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/openssl-fix-des.pod-error.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/openssl-util-perlpath.pl-cwd.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/openssl-util-perlpath.pl-cwd.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/openssl_fix_for_x32.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/openssl_fix_for_x32.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/parallel.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/parallel.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/ptest-deps.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/ptest-deps.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/ptest_makefile_deps.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/ptest_makefile_deps.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/run-ptest [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/run-ptest with 100% similarity]
meta/recipes-connectivity/openssl/openssl-1.0.2m/shared-libs.patch [moved from meta/recipes-connectivity/openssl/openssl-1.0.2l/shared-libs.patch with 100% similarity]
meta/recipes-connectivity/openssl/openssl_1.0.2m.bb [moved from meta/recipes-connectivity/openssl/openssl_1.0.2l.bb with 94% similarity]

similarity index 94%
rename from meta/recipes-connectivity/openssl/openssl_1.0.2l.bb
rename to meta/recipes-connectivity/openssl/openssl_1.0.2m.bb
index c537aa4cd0a29c4a845f3b8925acc50ef7f90bde..04763ac3469a08f387f556edbf99a5b308b73f05 100644 (file)
@@ -43,8 +43,8 @@ SRC_URI += "file://find.pl;subdir=openssl-${PV}/util/ \
             file://0001-Fix-build-with-clang-using-external-assembler.patch \
             file://0001-openssl-force-soft-link-to-avoid-rare-race.patch  \
             "
-SRC_URI[md5sum] = "f85123cd390e864dfbe517e7616e6566"
-SRC_URI[sha256sum] = "ce07195b659e75f4e1db43552860070061f156a98bb37b672b101ba6e3ddf30c"
+SRC_URI[md5sum] = "10e9e37f492094b9ef296f68f24a7666"
+SRC_URI[sha256sum] = "8c6ff15ec6b319b50788f42c7abc2890c08ba5a1cdcd3810eb9092deada37b0f"
 
 PACKAGES =+ "${PN}-engines"
 FILES_${PN}-engines = "${libdir}/ssl/engines/*.so ${libdir}/engines"