Skip to content
This repository has been archived by the owner on Jul 14, 2021. It is now read-only.

Update libcurl to 7.65, openssl to 1.0.2s, and ca-certs to 2019-05-11 #2107

Merged
merged 1 commit into from
May 28, 2019

Conversation

tas50
Copy link
Contributor

@tas50 tas50 commented May 28, 2019

Update omnibus defs:

New ca-cert includes this new certs:

  • emSign Root CA - G1
  • emSign ECC Root CA - G3
  • emSign Root CA - C1
  • emSign ECC Root CA - C3
  • Hongkong Post Root CA 3

New libcurl fixes these CVEs:

Signed-off-by: Tim Smith tsmith@chef.io

Update omnibus defs:

New ca-cert includes this new certs:

- emSign Root CA - G1
- emSign ECC Root CA - G3
- emSign Root CA - C1
- emSign ECC Root CA - C3
- Hongkong Post Root CA 3

New libcurl fixes these CVEs:
- CVE-2019-5435: Integer overflows in curl_url_set
- CVE-2019-5436: tftp: use the current blksize for recvfrom()
- CVE-2018-16890: NTLM type-2 out-of-bounds buffer read
- CVE-2019-3822: NTLMv2 type-3 header stack buffer overflow
- CVE-2019-3823: SMTP end-of-response out-of-bounds read

Signed-off-by: Tim Smith <tsmith@chef.io>
@tas50 tas50 requested a review from tyler-ball May 28, 2019 18:35
@tas50 tas50 merged commit df245a9 into master May 28, 2019
@chef-ci chef-ci deleted the bumps branch May 28, 2019 18:41
@lock
Copy link

lock bot commented Jul 27, 2019

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock bot locked as resolved and limited conversation to collaborators Jul 27, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants