]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
package/berkeleydb: add security fix for CVE-2017-10140
authorBernd Kuhls <bernd.kuhls@t-online.de>
Sat, 27 Jan 2018 22:41:21 +0000 (23:41 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 31 Jan 2018 12:09:18 +0000 (13:09 +0100)
commit8207b3ad28c470f06d356642ea3516354421a590
tree74354ed4a9198c92cc427a08956500ccded32046
parente4755cd898212bd42af816ba50cde2d46477daaf
package/berkeleydb: add security fix for CVE-2017-10140

Fixes CVE-2017-10140: Berkeley DB reads DB_CONFIG from cwd

For more details, see:
https://security-tracker.debian.org/tracker/CVE-2017-10140

And add license hash while we are at it.

[Peter: extend commit message]
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 0b368023f7e166648f136244960608a0e009332d)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/berkeleydb/0001-cwd-db_config.patch [new file with mode: 0644]
package/berkeleydb/berkeleydb.hash