From 79c77a6e7fdf162e5609d46b00c99a7d177a381b Mon Sep 17 00:00:00 2001 From: Gustavo Zacarias Date: Mon, 4 Aug 2014 14:48:02 -0300 Subject: [PATCH] gnupg2: security bump to version 2.0.25 Fixes CVE-2014-4617 (The do_uncompress function in g10/compress.c allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence. Signed-off-by: Gustavo Zacarias Signed-off-by: Thomas Petazzoni --- package/gnupg2/gnupg2.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/gnupg2/gnupg2.mk b/package/gnupg2/gnupg2.mk index fd35e6e3fa..9502a8241b 100644 --- a/package/gnupg2/gnupg2.mk +++ b/package/gnupg2/gnupg2.mk @@ -4,7 +4,7 @@ # ################################################################################ -GNUPG2_VERSION = 2.0.23 +GNUPG2_VERSION = 2.0.25 GNUPG2_SOURCE = gnupg-$(GNUPG2_VERSION).tar.bz2 GNUPG2_SITE = ftp://ftp.gnupg.org/gcrypt/gnupg GNUPG2_LICENSE = GPLv3+