Skip to content

Commit

Permalink
botan2: 2.19.4 -> 2.19.5
Browse files Browse the repository at this point in the history
Changelog: https://botan.randombit.net/news.html#version-2-19-5-2024-07-08

CVEs fixed:
- CVE-2024-34702: Fix a DoS caused by excessive name constraints. (GH #4187)
- CVE-2024-39312: Fix a name constraint processing error, where if permitted
  and excluded rules both applied to a certificate, only the permitted rules would be checked. (GH #4187)

Other changes:
- Fix a crash in OCB

The authors of botan also added the following to the changelog:
"A reminder that Botan2 reaches end of life at the end of 2024"

Signed-off-by: Markus Theil <[email protected]>
(cherry picked from commit 4e5416b)
  • Loading branch information
thillux committed Jul 17, 2024
1 parent 04d2e0d commit 3fd3ce5
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions pkgs/development/libraries/botan/2.0.nix
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

callPackage ./generic.nix (args // {
baseVersion = "2.19";
revision = "4";
hash = "sha256-WjqI72Qz6XvKsO+h7WDGGX5K2p2dMLwcR0N7+JuX8nY=";
revision = "5";
hash = "sha256-3+6g4KbybWckxK8B2pp7iEh62y2Bunxy/K9S21IsmtQ=";
})

0 comments on commit 3fd3ce5

Please sign in to comment.