Thanks, applied as 8a1428c641a8f985553885a38d50c39c926824b4. Michael
[sent from post-receive hook] On Mon, 05 Aug 2024 08:50:02 +0200, Christian Melki <[email protected]> wrote: > https://curl.se/changes.html#8_9_0 > Plug CVEs: > CVE-2024-6874 - macidn punycode buffer overread > CVE-2024-6197 - freeing stack buffer in utf8asn1str > > * Rearrange one option and set a new option. > > Signed-off-by: Christian Melki <[email protected]> > Message-Id: <[email protected]> > Signed-off-by: Michael Olbrich <[email protected]> > > diff --git a/rules/libcurl.make b/rules/libcurl.make > index 65c9714b264e..b5008117f737 100644 > --- a/rules/libcurl.make > +++ b/rules/libcurl.make > @@ -15,8 +15,8 @@ PACKAGES-$(PTXCONF_LIBCURL) += libcurl > # > # Paths and names > # > -LIBCURL_VERSION := 8.8.0 > -LIBCURL_MD5 := e1062de8a9b252a75fc42e2252746bd8 > +LIBCURL_VERSION := 8.9.0 > +LIBCURL_MD5 := 6f6d2ff25c2a8fa8602511dc33201cc4 > LIBCURL := curl-$(LIBCURL_VERSION) > LIBCURL_SUFFIX := tar.xz > LIBCURL_URL := https://curl.se/download/$(LIBCURL).$(LIBCURL_SUFFIX) > @@ -43,6 +43,7 @@ LIBCURL_CONF_OPT := \ > --enable-symbol-hiding \ > --$(call ptx/endis, PTXCONF_LIBCURL_C_ARES)-ares \ > --enable-rt \ > + --disable-httpsrr \ > --disable-ech \ > --disable-code-coverage \ > $(GLOBAL_LARGE_FILE_OPTION) \ > @@ -62,8 +63,8 @@ LIBCURL_CONF_OPT := \ > --$(call ptx/endis, PTXCONF_LIBCURL_SMTP)-smtp \ > --disable-gopher \ > --disable-mqtt \ > - --disable-docs \ > --disable-manual \ > + --disable-docs \ > --enable-libcurl-option \ > --disable-libgcc \ > $(GLOBAL_IPV6_OPTION) \
