Re: [LEDE-DEV] [PATCH] mbedtls: update to 2.5.1

2017-06-24 Thread Daniel Engberg
Hi, This is exactly why I want to add https://github.com/lede-project/source/pull/1133 so we don't need to chase around for odd mirrors. :-) Best regards, Daniel ___ Lede-dev mailing list Lede-dev@lists.infradead.org http://lists.infradead.org/mail

[LEDE-DEV] [PATCH] mbedtls: update to 2.5.1

2017-06-21 Thread Magnus Kroken
Fixes some security issues (no remote exploits), and introduces some changes. See release notes for details: https://tls.mbed.org/tech-updates/releases/mbedtls-2.5.1-2.1.8-and-1.3.20-released * Fixes an unlimited overread of heap-based buffers in mbedtls_ssl_read() * Adds exponent blinding to RSA