path: root/package/wolfssl/wolfssl.hash
diff options
authorGravatar Peter Korsgaard <peter@korsgaard.com>2019-01-16 13:45:21 +0100
committerGravatar Peter Korsgaard <peter@korsgaard.com>2019-01-25 08:33:53 +0100
commit3ff4fafbb1a74de336bfcbfb33b6087dc62bc7a7 (patch)
tree9d5b4ff8a391aae61dbb45686ee77a91a1392c5a /package/wolfssl/wolfssl.hash
parent3dfa23c33bc4bbee2d6193a0017e7b55cbaae463 (diff)
package/wolfssl: security bump to version 3.5.17
From the release notes: This release of wolfSSL includes a fix for 1 security vulnerability. Medium level fix for potential cache attack with a variant of Bleichenbacher’s attack. Earlier versions of wolfSSL leaked PKCS #1 v1.5 padding information during private key decryption that could lead to a potential padding oracle attack. It is recommended that users update to the latest version of wolfSSL if they have RSA cipher suites enabled and have the potential for malicious software to be ran on the same system that is performing RSA operations. Users that have only ECC cipher suites enabled and are not performing RSA PKCS #1 v1.5 Decryption operations are not vulnerable. Also users with TLS 1.3 only connections are not vulnerable to this attack. Thanks to Eyal Ronen (Weizmann Institute), Robert Gillham (University of Adelaide), Daniel Genkin (University of Michigan), Adi Shamir (Weizmann Institute), David Wong (NCC Group), and Yuval Yarom (University of Adelaide and Data61) for the report. The paper for further reading on the attack details can be found at http://cat.eyalro.net/cat.pdf Drop now upstreamed patch. Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 4e1b3c6e9f9096f0906ff508c21818408bd1e4b6) Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/wolfssl/wolfssl.hash')
1 files changed, 1 insertions, 1 deletions
diff --git a/package/wolfssl/wolfssl.hash b/package/wolfssl/wolfssl.hash
index 2fdaa5762b..1ff9fc61d8 100644
--- a/package/wolfssl/wolfssl.hash
+++ b/package/wolfssl/wolfssl.hash
@@ -1,5 +1,5 @@
# Locally computed:
-sha256 4e15f494604e41725499f8b708798f8ddc2fcaa8f39b4369bcd000b3cab482d8 v3.15.5-stable.tar.gz
+sha256 70e4fbeb91284a269b25a84fc526755c670475aee4034a6f237b1f754d108af3 v3.15.7-stable.tar.gz
# Hash for license files:
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING