immortalwrt/package
Andre Heider 06892d7fbb
openssl: bump to 1.1.1p
Changes between 1.1.1o and 1.1.1p [21 Jun 2022]

  *) In addition to the c_rehash shell command injection identified in
     CVE-2022-1292, further bugs where the c_rehash script does not
     properly sanitise shell metacharacters to prevent command injection have been
     fixed.

     When the CVE-2022-1292 was fixed it was not discovered that there
     are other places in the script where the file names of certificates
     being hashed were possibly passed to a command executed through the shell.

     This script is distributed by some operating systems in a manner where
     it is automatically executed.  On such operating systems, an attacker
     could execute arbitrary commands with the privileges of the script.

     Use of the c_rehash script is considered obsolete and should be replaced
     by the OpenSSL rehash command line tool.
     (CVE-2022-2068)
     [Daniel Fiala, Tomáš Mráz]

  *) When OpenSSL TLS client is connecting without any supported elliptic
     curves and TLS-1.3 protocol is disabled the connection will no longer fail
     if a ciphersuite that does not use a key exchange based on elliptic
     curves can be negotiated.
     [Tomáš Mráz]

Signed-off-by: Andre Heider <a.heider@gmail.com>
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2022-07-04 16:54:06 +08:00
..
base-files ImmortalWrt v21.02.0: revert to branch defaults 2022-04-22 07:11:48 +08:00
boot x86: grub2: search for the "kernel" filesystem on all disks 2022-04-21 16:43:31 +08:00
devel Merge Official Source 2021-04-12 02:22:36 +08:00
emortal default-settings: update tencent ntp server 2022-06-20 03:27:32 +08:00
firmware ipq40xx: add support for ASUS RT-ACRH17/RT-AC42U 2022-06-30 15:43:02 +08:00
kernel Merge Official Source 2022-07-04 16:37:45 +08:00
libs openssl: bump to 1.1.1p 2022-07-04 16:54:06 +08:00
network dnsmasq: enable cache by default 2022-06-05 20:36:49 +08:00
system package: fix cmake packages build with ninja 2022-05-18 12:09:41 +08:00
utils Merge Official Source 2022-01-10 20:26:41 +08:00
Makefile build: fix opkg install step for large package selection 2021-12-31 17:55:29 +01:00