gluon/patches/packages/packages
Matthias Schiffer 2b5d4b88b4
ecdsautils: verify: fix signature verification (CVE-2022-24884)
A vulnerability was found in ecdsautils which allows forgery of ECDSA
signatures. An adversary exploiting this vulnerability can create an update
manifest accepted by the autoupdater, which can be used to distribute
malicious firmware updates by spoofing a Gluon node's connection to the
update server.
2022-05-03 07:36:23 +02:00
..
0001-fastd-update-to-v19.patch fastd: reorganize patches for easier backporting 2020-10-19 23:13:50 +02:00
0002-fastd-update-to-v21.patch fastd: reorganize patches for easier backporting 2020-10-19 23:13:50 +02:00
0003-perl-don-t-build-in-parallel-and-bump-release.patch patches: build perl single-threaded (#2392) 2022-02-22 18:57:02 +01:00
0004-ecdsautils-verify-fix-signature-verification-CVE-2022-24884.patch ecdsautils: verify: fix signature verification (CVE-2022-24884) 2022-05-03 07:36:23 +02:00