Fixes CVE-2018-0500: curl might overflow a heap based memory buffer when
sending data over SMTP and using a reduced read buffer.
Drop upstream patch.
Add reference to tarball signature key.
Drop CRYPTO_lock seed. Removed from configure script since 7.45.
Cc: Matt Weber <matthew.weber@rockwellcollins.com>
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit bf79731153
)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
6 lines
330 B
Plaintext
6 lines
330 B
Plaintext
# Locally calculated after checking pgp signature
|
|
# https://curl.haxx.se/download/curl-7.61.0.tar.xz.asc
|
|
# with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
|
|
sha256 ef6e55192d04713673b4409ccbcb4cb6cd723137d6e10ca45b0c593a454e1720 curl-7.61.0.tar.xz
|
|
sha256 5f3849ec38ddb927e79f514bf948890c41b8d1407286a49609b8fb1585931095 COPYING
|