mirror of
https://git.yoctoproject.org/poky
synced 2026-09-14 21:49:33 +02:00
Fixes following vulnerabilities: Certificate verify crash with missing PSS parameter (CVE-2015-3194) X509_ATTRIBUTE memory leak (CVE-2015-3195) References: https://openssl.org/news/secadv/20151203.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3194 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3195 Upstream patches: CVE-2015-3194: https://git.openssl.org/?p=openssl.git;a=commit;h= d8541d7e9e63bf5f343af24644046c8d96498c17 CVE-2015-3195: https://git.openssl.org/?p=openssl.git;a=commit;h= b29ffa392e839d05171206523e84909146f7a77c (From OE-Core rev: 09c3a0f01572a6a65e9f87ce16817ee7de3296f1) Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com> Signed-off-by: Armin Kuster <akuster808@gmail.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
58 lines
1.9 KiB
BlitzBasic
58 lines
1.9 KiB
BlitzBasic
require openssl.inc
|
|
|
|
# For target side versions of openssl enable support for OCF Linux driver
|
|
# if they are available.
|
|
DEPENDS += "cryptodev-linux"
|
|
|
|
CFLAG += "-DHAVE_CRYPTODEV -DUSE_CRYPTODEV_DIGESTS"
|
|
|
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=f9a8f968107345e0b75aa8c2ecaa7ec8"
|
|
|
|
export DIRS = "crypto ssl apps engines"
|
|
export OE_LDFLAGS="${LDFLAGS}"
|
|
|
|
SRC_URI += "file://configure-targets.patch \
|
|
file://shared-libs.patch \
|
|
file://oe-ldflags.patch \
|
|
file://engines-install-in-libdir-ssl.patch \
|
|
file://debian/version-script.patch \
|
|
file://debian/pic.patch \
|
|
file://debian/c_rehash-compat.patch \
|
|
file://debian/ca.patch \
|
|
file://debian/make-targets.patch \
|
|
file://debian/no-rpath.patch \
|
|
file://debian/man-dir.patch \
|
|
file://debian/man-section.patch \
|
|
file://debian/no-symbolic.patch \
|
|
file://debian/debian-targets.patch \
|
|
file://openssl_fix_for_x32.patch \
|
|
file://fix-cipher-des-ede3-cfb1.patch \
|
|
file://openssl-avoid-NULL-pointer-dereference-in-EVP_DigestInit_ex.patch \
|
|
file://initial-aarch64-bits.patch \
|
|
file://find.pl \
|
|
file://openssl-fix-des.pod-error.patch \
|
|
file://Makefiles-ptest.patch \
|
|
file://ptest-deps.patch \
|
|
file://run-ptest \
|
|
file://CVE-2015-3194-Add-PSS-parameter-check.patch \
|
|
file://CVE-2015-3195-Fix-leak-with-ASN.1-combine.patch \
|
|
"
|
|
|
|
SRC_URI[md5sum] = "7563e92327199e0067ccd0f79f436976"
|
|
SRC_URI[sha256sum] = "bd5ee6803165c0fb60bbecbacacf244f1f90d2aa0d71353af610c29121e9b2f1"
|
|
|
|
PACKAGES =+ " \
|
|
${PN}-engines \
|
|
${PN}-engines-dbg \
|
|
"
|
|
|
|
FILES_${PN}-engines = "${libdir}/ssl/engines/*.so ${libdir}/engines"
|
|
FILES_${PN}-engines-dbg = "${libdir}/ssl/engines/.debug"
|
|
|
|
PARALLEL_MAKE = ""
|
|
PARALLEL_MAKEINST = ""
|
|
|
|
do_configure_prepend() {
|
|
cp ${WORKDIR}/find.pl ${S}/util/find.pl
|
|
}
|