openwrt/package
Petr Štetiar a596a8396b wolfssl: fix TLSv1.3 RCE in uhttpd by using latest 5.5.1-stable release
Fixes denial of service attack and buffer overflow against TLS 1.3
servers using session ticket resumption. When built with
--enable-session-ticket and making use of TLS 1.3 server code in
wolfSSL, there is the possibility of a malicious client to craft a
malformed second ClientHello packet that causes the server to crash.

This issue is limited to when using both --enable-session-ticket and TLS
1.3 on the server side. Users with TLS 1.3 servers, and having
--enable-session-ticket, should update to the latest version of wolfSSL.

Thanks to Max at Trail of Bits for the report and "LORIA, INRIA, France"
for research on tlspuffin.

Complete release notes https://github.com/wolfSSL/wolfssl/releases/tag/v5.5.1-stable

Fixes: https://github.com/openwrt/luci/issues/5962
References: https://github.com/wolfSSL/wolfssl/issues/5629
Signed-off-by: Petr Štetiar <ynezz@true.cz>
2022-09-29 07:36:19 +02:00
..
base-files base-files: Actually set default name 2022-09-22 21:37:45 +02:00
boot arm-trusted-firmware-mvebu: stop cluttering Image Builder 2022-09-21 13:06:10 +02:00
devel strace: replace PKG_CPE_ID 2022-09-06 16:36:36 +01:00
firmware ipq40xx: Add ZTE MF289F 2022-09-24 23:53:53 +02:00
kernel kernel: netsupport: replace insmod by modprobe 2022-09-27 17:16:45 +02:00
libs wolfssl: fix TLSv1.3 RCE in uhttpd by using latest 5.5.1-stable release 2022-09-29 07:36:19 +02:00
network qos-scripts: fix trailing whitespace in config files 2022-09-27 17:16:46 +02:00
system rpcd: update to latest Git HEAD 2022-09-16 15:15:20 +02:00
utils ucode: update to latest Git HEAD 2022-09-16 15:15:20 +02:00
Makefile build: fix opkg install step for large package selection 2021-05-12 11:13:53 +02:00