0ade2b2bc6
The fix in 1.6.2 for CVE-2022-3515 was found to be incomplete¹. This release fixes a related bug in the code to parse CRL signatures. Use a glob to match all gnupg tarballs rather than having fedpkg add each one to .gitignore. Also ignore rpm's, extracted source dirs, and the mock build results directory. ¹ https://gnupg.org/blog/20221017-pepe-left-the-ksba.html#sec-2-2
3 lines
328 B
Plaintext
3 lines
328 B
Plaintext
SHA512 (libksba-1.6.3.tar.bz2) = 188f6d27b4904c10cd54ba949c1132dd6c167f53dd1b77eae39c5b8e3ac8b15e87b2a54cdfddac95ac4ed41ee83c3d4e1b17d95126f245b6c204fade6739a2ce
|
|
SHA512 (libksba-1.6.3.tar.bz2.sig) = 57081497e32af41abbe84678dfb2379318ae75fdde1f871f3960b7dce7270b952a832b64accbb2a1f19fbef8db9f4d35ac59890ac6cbe45215a65f6971ba43f1
|