openssl_1_1: 1.1.1n -> 1.1.1o

Fixes command injection in the c_rehash script, which at the same time
is also considered obsolete and should be replaced by openssl rehash.

https://mta.openssl.org/pipermail/openssl-announce/2022-May/000224.html

Fixes: CVE-2022-1292
This commit is contained in:
Martin Weinelt 2022-05-03 18:05:18 +02:00
parent 00dc0eecc7
commit a7be3b2607
No known key found for this signature in database
GPG Key ID: 87C1E9888F856759

View File

@ -178,8 +178,8 @@ in {
openssl_1_1 = common rec {
version = "1.1.1n";
sha256 = "sha256-QNzrUaT2pSdb3g5r8g70uRv8Mu1XwFUuLo4VRjNysXo=";
version = "1.1.1o";
sha256 = "sha256-k4SisFcN2ANYhBRkZ3EV33he25QccSEfdQdtcv5rQ48=";
patches = [
./1.1/nix-ssl-cert-file.patch