gluon/patches/packages/packages
Matthias Schiffer 6eb0720e50
ecdsautils: verify: fix signature verification (CVE-2022-24884)
A vulnerability was found in ecdsautils which allows forgery of ECDSA
signatures. An adversary exploiting this vulnerability can create an update
manifest accepted by the autoupdater, which can be used to distribute
malicious firmware updates by spoofing a Gluon node's connection to the
update server.
2022-05-03 18:02:13 +02:00
..
0001-perl-fix-build-failure-in-GCC10.patch patches: packages: perl: backport GCC10 build fix 2020-10-12 23:57:01 +02:00
0002-ecdsautils-verify-fix-signature-verification-CVE-2022-24884.patch ecdsautils: verify: fix signature verification (CVE-2022-24884) 2022-05-03 18:02:13 +02:00