openssl: bump to 1.1.1d
authorEneas U de Queiroz <cotequeiroz@gmail.com>
Tue, 17 Sep 2019 13:52:11 +0000 (10:52 -0300)
committerPetr Štetiar <ynezz@true.cz>
Mon, 23 Sep 2019 05:42:30 +0000 (07:42 +0200)
commitb610572a9baf18a913231e5d90348af873986ddc
treed145d426dabbceba8bd37fcdafcd25ff2cc6db90
parent0b9f3c28ef6c37b42abdd02c19c96fe34d81ea33
openssl: bump to 1.1.1d

This version fixes 3 low-severity vulnerabilities:

- CVE-2019-1547: ECDSA remote timing attack
- CVE-2019-1549: Fork Protection
- CVE-2019-1563: Padding Oracle in PKCS7_dataDecode and
 CMS_decrypt_set1_pkey

Patches were refreshed.

Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com>
(cherry picked from commit d868d0a5d7e1d76bb1a8980346d222fae55fa18b)
12 files changed:
package/libs/openssl/Makefile
package/libs/openssl/patches/100-Configure-afalg-support.patch
package/libs/openssl/patches/110-openwrt_targets.patch
package/libs/openssl/patches/120-strip-cflags-from-binary.patch
package/libs/openssl/patches/130-dont-build-tests-fuzz.patch
package/libs/openssl/patches/140-allow-prefer-chacha20.patch
package/libs/openssl/patches/400-eng_devcrypto-save-ioctl-if-EVP_MD_.FLAG_ONESHOT.patch
package/libs/openssl/patches/410-eng_devcrypto-add-configuration-options.patch
package/libs/openssl/patches/420-eng_devcrypto-add-command-to-dump-driver-info.patch
package/libs/openssl/patches/430-e_devcrypto-make-the-dev-crypto-engine-dynamic.patch
package/libs/openssl/patches/500-e_devcrypto-default-to-not-use-digests-in-engine.patch
package/libs/openssl/patches/510-e_devcrypto-ignore-error-when-closing-session.patch