aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGravatar Martin Bark <martin@barkynet.com>2020-06-03 20:31:50 +0100
committerGravatar Yann E. MORIN <yann.morin.1998@free.fr>2020-06-03 23:00:06 +0200
commite500367ea44adffcfc3132099bedf550d9913313 (patch)
treed812cfe0bc42e9bd7701d861a848cf5c7fc7ea56
parent27812eb5218989b1250d599aa7b5ae28e32eaffb (diff)
downloadbuildroot-e500367ea44adffcfc3132099bedf550d9913313.tar.gz
buildroot-e500367ea44adffcfc3132099bedf550d9913313.tar.bz2
package/nghttp2: security bump version to 1.41.0
Fix CVE-2020-11080 Denial of service: Overly large SETTINGS frames Signed-off-by: Martin Bark <martin@barkynet.com> [yann.morin.1998@free.fr: two spaces in hash files] Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
-rw-r--r--package/nghttp2/nghttp2.hash4
-rw-r--r--package/nghttp2/nghttp2.mk2
2 files changed, 3 insertions, 3 deletions
diff --git a/package/nghttp2/nghttp2.hash b/package/nghttp2/nghttp2.hash
index e0512e891b..3702a91b5e 100644
--- a/package/nghttp2/nghttp2.hash
+++ b/package/nghttp2/nghttp2.hash
@@ -1,3 +1,3 @@
# Locally calculated
-sha256 fc820a305e2f410fade1a3260f09229f15c0494fc089b0100312cd64a33a38c0 nghttp2-1.39.2.tar.gz
-sha256 6b94f3abc1aabd0c72a7c7d92a77f79dda7c8a0cb3df839a97890b4116a2de2a COPYING
+sha256 eacc6f0f8543583ecd659faf0a3f906ed03826f1d4157b536b4b385fe47c5bb8 nghttp2-1.41.0.tar.gz
+sha256 6b94f3abc1aabd0c72a7c7d92a77f79dda7c8a0cb3df839a97890b4116a2de2a COPYING
diff --git a/package/nghttp2/nghttp2.mk b/package/nghttp2/nghttp2.mk
index 6a5ec72847..7b611c88fd 100644
--- a/package/nghttp2/nghttp2.mk
+++ b/package/nghttp2/nghttp2.mk
@@ -4,7 +4,7 @@
#
################################################################################
-NGHTTP2_VERSION = 1.39.2
+NGHTTP2_VERSION = 1.41.0
NGHTTP2_SITE = https://github.com/nghttp2/nghttp2/releases/download/v$(NGHTTP2_VERSION)
NGHTTP2_LICENSE = MIT
NGHTTP2_LICENSE_FILES = COPYING