[{"id":1764603,"web_url":"http://patchwork.ozlabs.org/comment/1764603/","msgid":"<87mv66dfya.fsf@dell.be.48ers.dk>","list_archive_url":null,"date":"2017-09-07T09:18:53","subject":"Re: [Buildroot] [PATCH 2/2] mbedtls: security bump to version 2.6.0","submitter":{"id":42365,"url":"http://patchwork.ozlabs.org/api/people/42365/","name":"Peter Korsgaard","email":"peter@korsgaard.com"},"content":">>>>> \"Baruch\" == Baruch Siach <baruch@tkos.co.il> writes:\n\n > Fixes CVE-2017-14032: authentication bypass.\n > https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02\n\n > Add license hash.\n\n > Cc: Gustavo Zacarias <gustavo@zacarias.com.ar>\n > Signed-off-by: Baruch Siach <baruch@tkos.co.il>\n\nCommitted, thanks.","headers":{"Return-Path":"<buildroot-bounces@busybox.net>","X-Original-To":["incoming@patchwork.ozlabs.org","buildroot@lists.busybox.net"],"Delivered-To":["patchwork-incoming@bilbo.ozlabs.org","buildroot@osuosl.org"],"Authentication-Results":["ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=busybox.net\n\t(client-ip=140.211.166.137; helo=fraxinus.osuosl.org;\n\tenvelope-from=buildroot-bounces@busybox.net;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (2048-bit key;\n\tunprotected) header.d=gmail.com header.i=@gmail.com\n\theader.b=\"JzfG8ENP\"; dkim-atps=neutral"],"Received":["from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137])\n\t(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xnvyv3trZz9sRV\n\tfor <incoming@patchwork.ozlabs.org>;\n\tThu,  7 Sep 2017 19:19:03 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby fraxinus.osuosl.org (Postfix) with ESMTP id 0B97087A35;\n\tThu,  7 Sep 2017 09:19:01 +0000 (UTC)","from fraxinus.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id u0uSfVEztrRN; Thu,  7 Sep 2017 09:18:59 +0000 (UTC)","from ash.osuosl.org (ash.osuosl.org [140.211.166.34])\n\tby fraxinus.osuosl.org (Postfix) with ESMTP id 62EE687A0A;\n\tThu,  7 Sep 2017 09:18:59 +0000 (UTC)","from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138])\n\tby ash.osuosl.org (Postfix) with ESMTP id 596C81C00E9\n\tfor <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 09:18:58 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id 52E1987D1C\n\tfor <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 09:18:58 +0000 (UTC)","from whitealder.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id Q-Ia3K-2ZueO for <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 09:18:57 +0000 (UTC)","from mail-wm0-f45.google.com (mail-wm0-f45.google.com\n\t[74.125.82.45])\n\tby whitealder.osuosl.org (Postfix) with ESMTPS id 2845188911\n\tfor <buildroot@busybox.net>; Thu,  7 Sep 2017 09:18:57 +0000 (UTC)","by mail-wm0-f45.google.com with SMTP id 137so32457458wmj.1\n\tfor <buildroot@busybox.net>; Thu, 07 Sep 2017 02:18:57 -0700 (PDT)","from dell.be.48ers.dk (d51A5BC31.access.telenet.be.\n\t[81.165.188.49]) by smtp.gmail.com with ESMTPSA id\n\tc30sm1481839edf.26.2017.09.07.02.18.54\n\t(version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);\n\tThu, 07 Sep 2017 02:18:54 -0700 (PDT)","from peko by dell.be.48ers.dk with local (Exim 4.88)\n\t(envelope-from <peter@korsgaard.com>)\n\tid 1dpsxZ-0002ao-OP; Thu, 07 Sep 2017 11:18:53 +0200"],"X-Virus-Scanned":["amavisd-new at osuosl.org","amavisd-new at osuosl.org"],"X-Greylist":"domain auto-whitelisted by SQLgrey-1.7.6","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;\n\th=sender:from:to:cc:subject:references:date:in-reply-to:message-id\n\t:user-agent:mime-version;\n\tbh=54eteFBm7mnfBgeiMVBu0H8/dsgFt62Q26GDGcFE1wY=;\n\tb=JzfG8ENPXhq4Al8Fe92Afk+fJ7lUgzvy5treaX85Cgj7xEB+iR4WRy2qsVv8BzScLR\n\tRRvabXWOIQtricPlwI/9HPMiVxHwsGV4ekC1MprKedyr4kR+Ue35UlEZpeJPBwUIPxvN\n\ttBAHHz2K+/DJ3M538jGcl/gMhB29CDUhVtV3wZGOwcBCv9VE21V0+IMxzKysbw7Aq/4t\n\t2ynSubPkFbXFb5yZZSROsohLK4IJtJrCnHhYME5oCbCksh1UIYx+mjXaOITnrvms++aa\n\tRtP+xd9VGonu6jaiv+y63/CEZE8qPJCQy4NLkBfAkhkibSrR4qe8JLJ9YHPICATkIKah\n\t+bNA==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:sender:from:to:cc:subject:references:date\n\t:in-reply-to:message-id:user-agent:mime-version;\n\tbh=54eteFBm7mnfBgeiMVBu0H8/dsgFt62Q26GDGcFE1wY=;\n\tb=WR2Akp16D4JQ6Ur0T2viSBKGSrJCoiFWicl/Rg6rEzRBVxmZEARZvsPA9Xma9EXaxE\n\tnk6vvv+nPUFlfuZ7UUz6kIvkLtmhJbuuI6ImrI5WOYaspCS+icmgLWcbEGsqFpDp/yOf\n\tnVCVSrVbZ5DeYU58XHA+1UJLbWv1WEnTbCU5wbQbdgjO30ChkvMZWV8IuURJptplJRtq\n\tbAil2rQj3aoVa32vYTQupNhb6BdPxRpI6kYCpMOnpvGighWW0YG/sJMOEJPChbV9602D\n\tFuvdjZ456HXHb2ukuYJLfNcJgfnhg0TZwugdCjXLN9tTSvnPC3wOrCGtUxCna747DRQf\n\ttPsA==","X-Gm-Message-State":"AHPjjUjFs4zst571Mela2vq/wBTqO8erWz1NobT9O6CiaoYhB6HAViDX\n\tBJWssRXme4Zc3ZVyRGw=","X-Google-Smtp-Source":"ADKCNb68DuRGwqEHd7UtMmsRHBu490C1jKmcbR44KUTZpceSqB/VBTvCkBhzOLzt0ima9G4kBtG7mg==","X-Received":"by 10.80.140.68 with SMTP id p62mr2037487edp.281.1504775935719; \n\tThu, 07 Sep 2017 02:18:55 -0700 (PDT)","From":"Peter Korsgaard <peter@korsgaard.com>","To":"Baruch Siach <baruch@tkos.co.il>","References":"<87aa32f0dbacc3252ade43fc605e7f2c310e6465.1504638326.git.baruch@tkos.co.il>\n\t<4340454882827bf3f55e05edde6241878a072857.1504638326.git.baruch@tkos.co.il>","Date":"Thu, 07 Sep 2017 11:18:53 +0200","In-Reply-To":"<4340454882827bf3f55e05edde6241878a072857.1504638326.git.baruch@tkos.co.il>\n\t(Baruch Siach's message of \"Tue, 5 Sep 2017 22:05:26 +0300\")","Message-ID":"<87mv66dfya.fsf@dell.be.48ers.dk>","User-Agent":"Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux)","MIME-Version":"1.0","Cc":"buildroot@busybox.net","Subject":"Re: [Buildroot] [PATCH 2/2] mbedtls: security bump to version 2.6.0","X-BeenThere":"buildroot@busybox.net","X-Mailman-Version":"2.1.18-1","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.busybox.net>","List-Unsubscribe":"<http://lists.busybox.net/mailman/options/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=unsubscribe>","List-Archive":"<http://lists.busybox.net/pipermail/buildroot/>","List-Post":"<mailto:buildroot@busybox.net>","List-Help":"<mailto:buildroot-request@busybox.net?subject=help>","List-Subscribe":"<http://lists.busybox.net/mailman/listinfo/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=subscribe>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@busybox.net","Sender":"\"buildroot\" <buildroot-bounces@busybox.net>"}},{"id":1764715,"web_url":"http://patchwork.ozlabs.org/comment/1764715/","msgid":"<87a826d4zt.fsf@dell.be.48ers.dk>","list_archive_url":null,"date":"2017-09-07T13:15:34","subject":"Re: [Buildroot] [PATCH 2/2] mbedtls: security bump to version 2.6.0","submitter":{"id":42365,"url":"http://patchwork.ozlabs.org/api/people/42365/","name":"Peter Korsgaard","email":"peter@korsgaard.com"},"content":">>>>> \"Baruch\" == Baruch Siach <baruch@tkos.co.il> writes:\n\n > Fixes CVE-2017-14032: authentication bypass.\n > https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02\n\n > Add license hash.\n\n > Cc: Gustavo Zacarias <gustavo@zacarias.com.ar>\n > Signed-off-by: Baruch Siach <baruch@tkos.co.il>\n\nCommitted to 2017.02.x, thanks.","headers":{"Return-Path":"<buildroot-bounces@busybox.net>","X-Original-To":["incoming@patchwork.ozlabs.org","buildroot@lists.busybox.net"],"Delivered-To":["patchwork-incoming@bilbo.ozlabs.org","buildroot@osuosl.org"],"Authentication-Results":["ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=busybox.net\n\t(client-ip=140.211.166.138; helo=whitealder.osuosl.org;\n\tenvelope-from=buildroot-bounces@busybox.net;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (2048-bit key;\n\tunprotected) header.d=gmail.com header.i=@gmail.com\n\theader.b=\"hSws2eO/\"; dkim-atps=neutral"],"Received":["from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138])\n\t(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xp1D21PRjz9sNd\n\tfor <incoming@patchwork.ozlabs.org>;\n\tThu,  7 Sep 2017 23:15:46 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id ED57188A59;\n\tThu,  7 Sep 2017 13:15:42 +0000 (UTC)","from whitealder.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id ZBs5ZJFkaiPy; Thu,  7 Sep 2017 13:15:41 +0000 (UTC)","from ash.osuosl.org (ash.osuosl.org [140.211.166.34])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id E819C88A26;\n\tThu,  7 Sep 2017 13:15:40 +0000 (UTC)","from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138])\n\tby ash.osuosl.org (Postfix) with ESMTP id 4BF391C01DA\n\tfor <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 13:15:39 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id 442BA88A26\n\tfor <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 13:15:39 +0000 (UTC)","from whitealder.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id 29PbsH3enUd0 for <buildroot@lists.busybox.net>;\n\tThu,  7 Sep 2017 13:15:38 +0000 (UTC)","from mail-wm0-f43.google.com (mail-wm0-f43.google.com\n\t[74.125.82.43])\n\tby whitealder.osuosl.org (Postfix) with ESMTPS id 08F3588A24\n\tfor <buildroot@busybox.net>; Thu,  7 Sep 2017 13:15:38 +0000 (UTC)","by mail-wm0-f43.google.com with SMTP id r10so3660739wmf.1\n\tfor <buildroot@busybox.net>; Thu, 07 Sep 2017 06:15:37 -0700 (PDT)","from dell.be.48ers.dk (d51A5BC31.access.telenet.be.\n\t[81.165.188.49]) by smtp.gmail.com with ESMTPSA id\n\tg59sm732604ede.6.2017.09.07.06.15.35\n\t(version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);\n\tThu, 07 Sep 2017 06:15:35 -0700 (PDT)","from peko by dell.be.48ers.dk with local (Exim 4.88)\n\t(envelope-from <peter@korsgaard.com>)\n\tid 1dpwec-0003hq-L0; Thu, 07 Sep 2017 15:15:34 +0200"],"X-Virus-Scanned":["amavisd-new at osuosl.org","amavisd-new at osuosl.org"],"X-Greylist":"domain auto-whitelisted by SQLgrey-1.7.6","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;\n\th=sender:from:to:cc:subject:references:date:in-reply-to:message-id\n\t:user-agent:mime-version;\n\tbh=DPH8h2U89K18Ymqc3DXLMwO/6v3F0MuX6vT9tmvgfJo=;\n\tb=hSws2eO/d5uKtEiuLzCgEVdD1++3DgxPkJ4DymvXP2XFpvA2Dhksz+xPfxnaOeOEvK\n\tESCDh9jGwP5ECZc8DrN0VcshPrZniL6wNR1ZXgSKXfYHUtyvhmeEKpFZfk7rZkBmLpqo\n\tU9Utc8YYGXpH7MyimZTYCZV83fFYlSyx5nf5k+9lGOe/RLwLJCQgMjKcXxXiVKiWZIEr\n\tORO3xxhOwRsm5qEyQ1tBm9Xm74nBNEYpMo46dYIjH72/VgU2UDStgqWcyakv3+oZZzoL\n\tE1MArmLhHX8jqJfrW0lzcRbQsHK+Bhh33TKll1rK//UsGOQkWYsy+uZg06ygmzYL+oAS\n\tmsjA==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:sender:from:to:cc:subject:references:date\n\t:in-reply-to:message-id:user-agent:mime-version;\n\tbh=DPH8h2U89K18Ymqc3DXLMwO/6v3F0MuX6vT9tmvgfJo=;\n\tb=Pp5Oq7FmCp2YdoXG3yZFzLcHff1WRLxgP8Km78JA+YUcjZDtWF87AfIwjk1wP2LBGh\n\tUfONI8GCrrpcx3rVS3v4LVxh8YGee9s7Y+gR2F6s9FoBv0a/j4MhhOH84ov0uVU8ECVU\n\t1HjVJuqB3hj++HrBRGYkNZR9nnFI3aI8BVUP4yBnLfL9zKlJFiG9yG7xiIUqqSXq2ffw\n\tIMB3kIIuHwd+2lAQunT51NKvnRQ+hUzcoX94B9DwCD2r0lT+CZn6Fk4Wfy/K5fj/7jcm\n\tCQfscabZGqB2WuhcPNwVavskpbxJVkRUjf9bJLbfHOy1WcFBglOrV/JFU2/J0u8raKBW\n\tZmiQ==","X-Gm-Message-State":"AHPjjUgxhFefp6kblut2jdVR6q/nWSpovBCltcIdtlVDqECwzEMTcEeH\n\tW4XzdRwKhUCBz6aIPGI=","X-Google-Smtp-Source":"ADKCNb4+UE9RZzo3QKa8fYpxsyvmaflNDvtkiWnYDrOYDd0LCl4dcV4h0Sd6x8CAYvHnNanc3rTBng==","X-Received":"by 10.80.207.77 with SMTP id d13mr2597545edk.106.1504790136464; \n\tThu, 07 Sep 2017 06:15:36 -0700 (PDT)","From":"Peter Korsgaard <peter@korsgaard.com>","To":"Baruch Siach <baruch@tkos.co.il>","References":"<87aa32f0dbacc3252ade43fc605e7f2c310e6465.1504638326.git.baruch@tkos.co.il>\n\t<4340454882827bf3f55e05edde6241878a072857.1504638326.git.baruch@tkos.co.il>","Date":"Thu, 07 Sep 2017 15:15:34 +0200","In-Reply-To":"<4340454882827bf3f55e05edde6241878a072857.1504638326.git.baruch@tkos.co.il>\n\t(Baruch Siach's message of \"Tue, 5 Sep 2017 22:05:26 +0300\")","Message-ID":"<87a826d4zt.fsf@dell.be.48ers.dk>","User-Agent":"Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux)","MIME-Version":"1.0","Cc":"buildroot@busybox.net","Subject":"Re: [Buildroot] [PATCH 2/2] mbedtls: security bump to version 2.6.0","X-BeenThere":"buildroot@busybox.net","X-Mailman-Version":"2.1.18-1","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.busybox.net>","List-Unsubscribe":"<http://lists.busybox.net/mailman/options/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=unsubscribe>","List-Archive":"<http://lists.busybox.net/pipermail/buildroot/>","List-Post":"<mailto:buildroot@busybox.net>","List-Help":"<mailto:buildroot-request@busybox.net?subject=help>","List-Subscribe":"<http://lists.busybox.net/mailman/listinfo/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=subscribe>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@busybox.net","Sender":"\"buildroot\" <buildroot-bounces@busybox.net>"}}]