summaryrefslogtreecommitdiff
path: root/package/gnupg2
diff options
context:
space:
mode:
authorBaruch Siach <baruch@tkos.co.il>2015-02-27 14:08:12 +0200
committerPeter Korsgaard <peter@korsgaard.com>2015-02-27 13:56:49 +0100
commitb17e5352cad1214f10ebed5ad68a9bfbcc280690 (patch)
tree347395c4689b4b1907e4a86f41df41c234ebb6ad /package/gnupg2
parent10900c071565004c3e2b22bd746c70772142d975 (diff)
gnupg2: security bump to version 2.0.27
Fixes: CVE-2015-1606: Use after free, resulting from failure to skip invalid packets CVE-2015-1607: memcpy with overlapping ranges, resulting from incorrect bitwise left shifts Signed-off-by: Baruch Siach <baruch@tkos.co.il> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/gnupg2')
-rw-r--r--package/gnupg2/gnupg2.hash4
-rw-r--r--package/gnupg2/gnupg2.mk2
2 files changed, 3 insertions, 3 deletions
diff --git a/package/gnupg2/gnupg2.hash b/package/gnupg2/gnupg2.hash
index 62fdaee91..404c40bed 100644
--- a/package/gnupg2/gnupg2.hash
+++ b/package/gnupg2/gnupg2.hash
@@ -1,2 +1,2 @@
-# Locally calculated after checking pgp signature
-sha256 7758e30dc382ae7a7167ed41b7f936aa50af5ea2d6fccdef663b5b750b65b8e0 gnupg-2.0.26.tar.bz2
+# From http://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000362.html
+sha1 d065be185f5bac8ea07b210ab7756e79b83b63d4 gnupg-2.0.27.tar.bz2
diff --git a/package/gnupg2/gnupg2.mk b/package/gnupg2/gnupg2.mk
index 2d133aa0d..aa35c36c5 100644
--- a/package/gnupg2/gnupg2.mk
+++ b/package/gnupg2/gnupg2.mk
@@ -4,7 +4,7 @@
#
################################################################################
-GNUPG2_VERSION = 2.0.26
+GNUPG2_VERSION = 2.0.27
GNUPG2_SOURCE = gnupg-$(GNUPG2_VERSION).tar.bz2
GNUPG2_SITE = ftp://ftp.gnupg.org/gcrypt/gnupg
GNUPG2_LICENSE = GPLv3+