Go to file
Peter Korsgaard 3301b6e1b2 libopenssl: security bump to version 1.0.2q
Fixes the following security vulnerabilities:

  *) Microarchitecture timing vulnerability in ECC scalar multiplication

     OpenSSL ECC scalar multiplication, used in e.g. ECDSA and ECDH, has been
     shown to be vulnerable to a microarchitecture timing side channel attack.
     An attacker with sufficient access to mount local timing attacks during
     ECDSA signature generation could recover the private key.

     This issue was reported to OpenSSL on 26th October 2018 by Alejandro
     Cabrera Aldaya, Billy Brumley, Sohaib ul Hassan, Cesar Pereida Garcia and
     Nicola Tuveri.
     (CVE-2018-5407)
     [Billy Brumley]

  *) Timing vulnerability in DSA signature generation

     The OpenSSL DSA signature algorithm has been shown to be vulnerable to a
     timing side channel attack. An attacker could use variations in the signing
     algorithm to recover the private key.

     This issue was reported to OpenSSL on 16th October 2018 by Samuel Weiser.
     (CVE-2018-0734)
     [Paul Dale]

For more information, see the changelog:
https://www.openssl.org/news/cl102.txt

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2018-11-29 16:29:46 +01:00
arch arch: drop BR2_GCC_TARGET_CPU_REVISION option 2018-10-01 14:52:32 +02:00
board board/pc: use frame pointer unwinder in linux.config 2018-11-23 10:43:24 +01:00
boot boot/syslinux: fix build with glibc 2.28+ 2018-11-19 22:37:15 +01:00
configs configs/orangepi_zero_plus2: needs host-openssl to build Linux 2018-11-27 09:52:44 +01:00
docs docs/website: update for 2018.02.8 2018-11-27 00:25:37 +01:00
fs fs/tar: add support for xattrs (thus capabilties) 2018-11-20 23:28:07 +01:00
linux linux: bump CIP to version v4.4.154-cip28 2018-11-29 15:48:17 +01:00
package libopenssl: security bump to version 1.0.2q 2018-11-29 16:29:46 +01:00
support support/graph-depends: fix package names starting with a non-alpha 2018-11-24 10:58:40 +01:00
system package/systemd: needs glibc 2018-11-22 17:15:33 +01:00
toolchain toolchain/toolchain-buildroot: enable glibc for all little-endian ARCs with atomic ops 2018-11-09 22:02:16 +01:00
utils utils/genrandconfig: add missing new line when creating the configuration 2018-11-18 08:37:11 +01:00
.defconfig
.flake8 .flake8: ignore utils/diffconfig 2018-03-13 22:37:54 +01:00
.gitignore
.gitlab-ci.yml .gitlab-ci.yml: update after addition of TestF2FS test case 2018-11-08 22:41:53 +01:00
.gitlab-ci.yml.in .gitlab-ci.yml: do runtime tests only on explicit trigger 2018-10-21 23:34:18 +02:00
CHANGES Update for 2018.02.8 2018-11-27 00:23:50 +01:00
Config.in Config.in: security hardening: disable FORTIFY_SOURCE for gcc < 6 2018-11-06 08:54:25 +01:00
Config.in.legacy libnftnl: drop useless BR2_PACKAGE_LIBNFTNL_XML 2018-11-19 22:39:12 +01:00
COPYING
DEVELOPERS ell: new package 2018-11-08 21:39:57 +01:00
Makefile Update for 2018.11-rc2 2018-11-21 08:44:25 +01:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches