[PATCH 21.02 0/5] backport fix for TLSv1.3 RCE in uhttpd by using 5.5.1-stable

2022-10-05 Thread Petr Štetiar
Hi, we need to upgrade wolfSSL to version 5.5.1 as it fixes several remotely exploitable vulnerabilities in TLS v1.3 protocol handling, so I suggest to do so by backporting following commits from 22.03 release. I've tested this change in x86/64 QEMU, using openwrt-21.02.3-x86-64-generic-squashfs

Re: [PATCH 21.02 0/5] backport fix for TLSv1.3 RCE in uhttpd by using 5.5.1-stable

2022-10-05 Thread Hauke Mehrtens
On 10/5/22 11:46, Petr Štetiar wrote: Hi, we need to upgrade wolfSSL to version 5.5.1 as it fixes several remotely exploitable vulnerabilities in TLS v1.3 protocol handling, so I suggest to do so by backporting following commits from 22.03 release. I've tested this change in x86/64 QEMU, using