[oe] [meta-oe][PATCH] libssh2: upgrade 1.4.3 -> 1.6.0

akuster808 akuster808 at gmail.com
Wed Jul 8 15:19:37 UTC 2015


is is possible to include a reference to the security fix?

1.5.0 release
Security Advisory: Using `SSH_MSG_KEXINIT` data unbounded, CVE-2015-1782


On 07/08/2015 12:40 AM, Li xin wrote:
> Update the checksum of COPYING,since the date in it has been changed,
> but the LICENSE has not been changed.
>
> Signed-off-by: Li Xin <lixin.fnst at cn.fujitsu.com>
> ---
>   .../recipes-support/libssh2/{libssh2_1.4.3.bb => libssh2_1.6.0.bb}  | 6 +++---
>   1 file changed, 3 insertions(+), 3 deletions(-)
>   rename meta-oe/recipes-support/libssh2/{libssh2_1.4.3.bb => libssh2_1.6.0.bb} (60%)
>
> diff --git a/meta-oe/recipes-support/libssh2/libssh2_1.4.3.bb b/meta-oe/recipes-support/libssh2/libssh2_1.6.0.bb
> similarity index 60%
> rename from meta-oe/recipes-support/libssh2/libssh2_1.4.3.bb
> rename to meta-oe/recipes-support/libssh2/libssh2_1.6.0.bb
> index b537663..022482c 100644
> --- a/meta-oe/recipes-support/libssh2/libssh2_1.4.3.bb
> +++ b/meta-oe/recipes-support/libssh2/libssh2_1.6.0.bb
> @@ -5,11 +5,11 @@ SECTION = "libs"
>   DEPENDS = "zlib openssl"
>
>   LICENSE = "BSD"
> -LIC_FILES_CHKSUM = "file://COPYING;md5=d00afe44f336a79a2ca7e1681ce14509"
> +LIC_FILES_CHKSUM = "file://COPYING;md5=c5cf34fc0acb44b082ef50ef5e4354ca"
>
>   SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz"
> -SRC_URI[md5sum] = "071004c60c5d6f90354ad1b701013a0b"
> -SRC_URI[sha256sum] = "eac6f85f9df9db2e6386906a6227eb2cd7b3245739561cad7d6dc1d5d021b96d"
> +SRC_URI[md5sum] = "00aabd6e714a5f42a4fb82ace20db1dd"
> +SRC_URI[sha256sum] = "5a202943a34a1d82a1c31f74094f2453c207bf9936093867f41414968c8e8215"
>
>   inherit autotools pkgconfig
>
>



More information about the Openembedded-devel mailing list