Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Apr 2018 11:52:24 +0000
From:      bugzilla-noreply@freebsd.org
To:        ports-bugs@FreeBSD.org
Subject:   [Bug 227455] [maintainer-update] security/botan2: update to 2.6.0
Message-ID:  <bug-227455-7788-pZcawdlB74@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-227455-7788@https.bugs.freebsd.org/bugzilla/>
References:  <bug-227455-7788@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D227455

--- Comment #1 from commit-hook@freebsd.org ---
A commit references this bug:

Author: krion
Date: Thu Apr 12 11:51:30 UTC 2018
New revision: 467146
URL: https://svnweb.freebsd.org/changeset/ports/467146

Log:
  Update to 2.6.0

  Bugfixes and some new features. Most notable fix:
  - CVE-2018-9860 Fix a bug decrypting TLS CBC ciphertexts which could
    for a malformed ciphertext cause the decryptor to read and HMAC an
    additional 64K bytes of data which is not part of the record. This
    could cause a crash if the read went into unmapped memory. No
    information leak or out of bounds write occurs.

  PR:           227455
  Submitted by: maintainer

Changes:
  head/security/botan2/Makefile
  head/security/botan2/distinfo
  head/security/botan2/pkg-plist

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-227455-7788-pZcawdlB74>