<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/chunkeey/package/libs, branch v18.06.8</title>
<subtitle>Staging tree of Christian Lamparter</subtitle>
<id>https://git.openwrt.org/openwrt/staging/chunkeey/atom?h=v18.06.8</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/chunkeey/atom?h=v18.06.8'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/'/>
<updated>2020-02-27T21:25:59Z</updated>
<entry>
<title>libubox: backport blobmsg_check_array() fix</title>
<updated>2020-02-27T21:25:59Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2020-02-27T21:25:59Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=82fbd857471292ca71dc06b05f11089962f33a4f'/>
<id>urn:sha1:82fbd857471292ca71dc06b05f11089962f33a4f</id>
<content type='text'>
Fixes: FS#2833
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
(backported from commit 955634b473284847e3c8281a6ac85655329d8b06)
</content>
</entry>
<entry>
<title>libubox: backport security patches</title>
<updated>2020-01-27T20:44:28Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2020-01-21T22:58:30Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=cc0a54e3326d6329d85106d93d4083df380dac09'/>
<id>urn:sha1:cc0a54e3326d6329d85106d93d4083df380dac09</id>
<content type='text'>
This backports some security relevant patches from libubox master. These
patches should not change the existing API and ABI so that old
applications still work like before without any recompilation.
Application can now also use more secure APIs.

The new more secure interfaces are also available, but not used.

OpenWrt master and 19.07 already have these patches by using a more
recent libubox version.

Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>mbedtls: update to 2.16.4</title>
<updated>2020-01-26T19:25:47Z</updated>
<author>
<name>Magnus Kroken</name>
</author>
<published>2020-01-25T17:33:41Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=f51d1c3b7c7604489884dd9df2776e94dab7d413'/>
<id>urn:sha1:f51d1c3b7c7604489884dd9df2776e94dab7d413</id>
<content type='text'>
Fixes side channel vulnerabilities in mbed TLS' implementation of ECDSA.

Release announcement:
https://tls.mbed.org/tech-updates/releases/mbedtls-2.16.4-and-2.7.13-released

Security advisory:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-12

Fixes:
 * CVE-2019-18222: Side channel attack on ECDSA

Signed-off-by: Magnus Kroken &lt;mkroken@gmail.com&gt;
(cherry picked from commit 6e96fd90471a49185bcfe9dcb4844d444674ecab)
</content>
</entry>
<entry>
<title>openssl: update to version 1.0.2u</title>
<updated>2020-01-01T15:57:32Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2020-01-01T09:52:11Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=85c4d374c2d885e5d1c5b6be308a39bb1e918735'/>
<id>urn:sha1:85c4d374c2d885e5d1c5b6be308a39bb1e918735</id>
<content type='text'>
Fixes CVE-2019-1551 (rsaz_512_sqr overflow bug) on x86_x64

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
</content>
</entry>
<entry>
<title>ustream-ssl: backport fix for CVE-2019-5101, CVE-2019-5102</title>
<updated>2019-11-05T14:12:18Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2019-11-05T14:07:55Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=9d401013fc61b0ca51cd557b9922052b2c3cce26'/>
<id>urn:sha1:9d401013fc61b0ca51cd557b9922052b2c3cce26</id>
<content type='text'>
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
(cherry picked from commit c5d5cdb759adc890ce6699117b7119acf280ce77)
</content>
</entry>
<entry>
<title>libpcap: update to 1.9.1</title>
<updated>2019-10-19T13:26:19Z</updated>
<author>
<name>DENG Qingfang</name>
</author>
<published>2019-10-12T16:28:32Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=96a87b90ef2e7cacd9f0affa44649e7e0a125edb'/>
<id>urn:sha1:96a87b90ef2e7cacd9f0affa44649e7e0a125edb</id>
<content type='text'>
Fixed CVEs:
	CVE-2018-16301
	CVE-2019-15161
	CVE-2019-15162
	CVE-2019-15163
	CVE-2019-15164
	CVE-2019-15165

Signed-off-by: DENG Qingfang &lt;dengqf6@mail2.sysu.edu.cn&gt;
(cherry picked from commit 44f11353de044834a442d3192b66579b99305720)
</content>
</entry>
<entry>
<title>libpcap: update to 1.9.0</title>
<updated>2019-10-19T13:25:45Z</updated>
<author>
<name>Syrone Wong</name>
</author>
<published>2018-07-26T14:46:38Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=a857fc2ded37aec2b9f743087a7752bb3c0b510b'/>
<id>urn:sha1:a857fc2ded37aec2b9f743087a7752bb3c0b510b</id>
<content type='text'>
001-Fix-compiler_state_t.ai-usage-when-INET6-is-not-defi.patch dropped due to upstream
002-Add-missing-compiler_state_t-parameter.patch dropped due to upstream

202-protocol_api.patch dropped due to implemented upstream by another way
upstream commit: https://github.com/the-tcpdump-group/libpcap/commit/55c690f6f834b4762697d7a134de439c9096c921
and renamed via: https://github.com/the-tcpdump-group/libpcap/commit/697b1f7e9b1d6f5a5be04f821d7c5dc62458bb3b

ead is the only user who use the protocol api, we have to use the new api since libpcap 1.9.0

Signed-off-by: Syrone Wong &lt;wong.syrone@gmail.com&gt;
</content>
</entry>
<entry>
<title>mbedtls: update to 2.16.3</title>
<updated>2019-09-21T19:11:21Z</updated>
<author>
<name>Magnus Kroken</name>
</author>
<published>2019-09-18T19:22:16Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=a63edb469128aeee7d5fbc93709a25716e982e28'/>
<id>urn:sha1:a63edb469128aeee7d5fbc93709a25716e982e28</id>
<content type='text'>
Remove 300-bn_mul.h-Use-optimized-MULADDC-code-only-on-ARM-6.patch,
the issue has been fixed upstream.

Signed-off-by: Magnus Kroken &lt;mkroken@gmail.com&gt;
(cherry picked from commit 49d96ffc5c47e40b7f3d99a91a42ea8a54a38bd9)
</content>
</entry>
<entry>
<title>mbedtls: Update to version 2.16.2</title>
<updated>2019-09-21T19:10:44Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2019-06-18T22:31:03Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=2698157d54a0dabafa39aa8b0caa8acef1f269df'/>
<id>urn:sha1:2698157d54a0dabafa39aa8b0caa8acef1f269df</id>
<content type='text'>
Signed-off-by: Josef Schlehofer &lt;josef.schlehofer@nic.cz&gt;
(cherry picked from commit a2f54f6d5d98211e9c58420eed8c67f4fca83665)
</content>
</entry>
<entry>
<title>openssl: bump to 1.0.2t, add maintainer</title>
<updated>2019-09-20T18:50:07Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2019-09-17T19:01:24Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/chunkeey/commit/?id=952bafa03cbc21df134374dc949970a50beb6585'/>
<id>urn:sha1:952bafa03cbc21df134374dc949970a50beb6585</id>
<content type='text'>
This version fixes 3 low-severity vulnerabilities:

- CVE-2019-1547: ECDSA remote timing attack
- CVE-2019-1549: Fork Protection
- CVE-2019-1563: Padding Oracle in PKCS7_dataDecode and
                 CMS_decrypt_set1_pkey

Patches were refreshed, and Eneas U de Queiroz added as maintainer.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
</content>
</entry>
</feed>
