Bug 12796

Summary: Update OpenSSL to Version 1.1.1g to patch CVE-2020-1967
Product: buildroot Reporter: Pete Morici <pmorici>
Component: Outdated packageAssignee: unassigned
Status: RESOLVED FIXED    
Severity: critical CC: buildroot
Priority: P5    
Version: 2020.02.1   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Host: Target:
Build:

Description Pete Morici 2020-04-21 20:55:44 UTC
See:
    https://www.openssl.org/news/secadv/20200421.txt

Recent versions of Buildroot use version 1.1.1f
Comment 1 Thomas Petazzoni 2020-04-22 05:09:24 UTC
Thanks, it's already fixed by https://git.buildroot.org/buildroot/commit/?id=849aee4f8805cce89376c0cd1ce23721436a90ac. As it is a security bump, it will be backported to our 2020.02.x LTS branch.