Thread (5 messages) 5 messages, 3 authors, 2021-08-04

[Buildroot] [PATCH 1/2] package/spice: security bump to version 0.15.0

From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: 2021-07-18 21:30:00

On Wed, 16 Jun 2021 08:10:01 +0200
Fabrice Fontaine [off-list ref] wrote:
Fix CVE-2021-20201: A flaw was found in spice in versions before
0.14.92. A DoS tool might make it easier for remote attackers to cause a
denial of service (CPU consumption) by performing many renegotiations
within a single connection.

https://gitlab.freedesktop.org/spice/spice/-/tags/v0.15.0

Signed-off-by: Fabrice Fontaine <redacted>
---
 package/spice/spice.hash | 2 +-
 package/spice/spice.mk   | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)
Both applied, thanks!

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help