Re: [OE-core] [PATCH 1/1] curl: Security Advisory - curl - CVE-2014-3613

2014-10-27 Thread Burton, Ross
On 27 October 2014 01:46, Chong Lu chong...@windriver.com wrote: This patch includes windows characters. Ha, thanks git/email/etc. Merged from the branch, thanks. Cheers, Ross -- ___ Openembedded-core mailing list

Re: [OE-core] [PATCH 1/1] curl: Security Advisory - curl - CVE-2014-3613

2014-10-26 Thread Chong Lu
On 10/25/2014 06:16 AM, Burton, Ross wrote: On 24 October 2014 10:20, Chong Lu chong...@windriver.com mailto:chong...@windriver.com wrote: meta/recipes-support/curl/curl/CVE-2014-3613.patch | 269 + ERROR: Command Error: exit status: 1 Output: Applying patch

[OE-core] [PATCH 1/1] curl: Security Advisory - curl - CVE-2014-3613

2014-10-24 Thread Chong Lu
By not detecting and rejecting domain names for partial literal IP addresses properly when parsing received HTTP cookies, libcurl can be fooled to both sending cookies to wrong sites and into allowing arbitrary sites to set cookies for others. Signed-off-by: Chong Lu chong...@windriver.com ---

Re: [OE-core] [PATCH 1/1] curl: Security Advisory - curl - CVE-2014-3613

2014-10-24 Thread Burton, Ross
On 24 October 2014 10:20, Chong Lu chong...@windriver.com wrote: meta/recipes-support/curl/curl/CVE-2014-3613.patch | 269 + ERROR: Command Error: exit status: 1 Output: Applying patch CVE-2014-3613.patch patching file lib/cookie.c patching file tests/data/test1105