Bug#940985: dnsmasq WFTBFS: Accesses ECC curves directly

2019-10-27 Thread Andreas Metzler
Control: tags -1 + patch fixed-upstream On 2019-09-23 Magnus Holmgren wrote: > Package: dnsmasq > Version: 2.80-1 > Tags: upstream > Severity: serious > dnsmasq_ecdsa_verify() (in crypto.c) uses the addresses of nettle_secp_256r1 > and nettle_secp_384r1 directly. As the comment in ecc-curve.h

Processed: Re: Bug#940985: dnsmasq WFTBFS: Accesses ECC curves directly

2019-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + patch fixed-upstream Bug #940985 [dnsmasq] dnsmasq WFTBFS: Accesses ECC curves directly Added tag(s) patch and fixed-upstream. -- 940985: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=940985 Debian Bug Tracking System Contact ow...@bugs.debian.org

Bug#940985: dnsmasq WFTBFS: Accesses ECC curves directly

2019-09-22 Thread Magnus Holmgren
Package: dnsmasq Version: 2.80-1 Tags: upstream Severity: serious dnsmasq_ecdsa_verify() (in crypto.c) uses the addresses of nettle_secp_256r1 and nettle_secp_384r1 directly. As the comment in ecc-curve.h explains, "Due to ABI subtleties, applications should not refer to these directly, but use