diff options
author | Ed Tanous <edtanous@google.com> | 2022-11-01 10:03:10 -0700 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2022-11-04 23:31:49 +0000 |
commit | 8a3bbee311a6e3b987db007f42efa3ee895a67ec (patch) | |
tree | 808612ffbeea31aa9783099b8fd71560448ce52b /scripts/lib/scriptpath.py | |
parent | b1b1c9232f2a14fec446476edd0e74cf863c1ead (diff) | |
download | poky-8a3bbee311a6e3b987db007f42efa3ee895a67ec.tar.gz |
openssl: Upgrade 3.0.5 -> 3.0.7
OpenSSL 3.0.5 includes a HIGH level security vulnerability [1].
Upgrade the recipe to point to 3.0.7.
CVE-2022-3358 is reported fixed in 3.0.6, so drop the patch for that as
well.
[1] https://www.openssl.org/news/vulnerabilities.html
Fixes CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
(From OE-Core rev: 48f9f92c547fac35ff398180a32a5b0829cd9fff)
Signed-off-by: Ed Tanous <edtanous@google.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a69ea1f7db96ec8b853573bd581438edd42ad6e0)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'scripts/lib/scriptpath.py')
0 files changed, 0 insertions, 0 deletions