]> code.ossystems Code Review - openembedded-core.git/commit
glibc: CVE-2015-8779
authorArmin Kuster <akuster@mvista.com>
Sun, 28 Feb 2016 18:53:33 +0000 (10:53 -0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 21 Mar 2016 15:48:21 +0000 (15:48 +0000)
commit01e9f306e0af4ea2d9fe611c1592b0f19d83f487
treefb7a3c56b7d58797027f8cde7f2fad9f433f4db1
parentbb6ce1334bfb3711428b4b82bca4c0d5339ee2f8
glibc: CVE-2015-8779

A stack overflow vulnerability in the catopen function was found, causing
applications which pass long strings to the catopen function to crash or,
potentially execute arbitrary code.

(From OE-Core rev: af20e323932caba8883c91dac610e1ba2b3d4ab5)

Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Robert Yang <liezhi.yang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/glibc/glibc/CVE-2015-8779.patch [new file with mode: 0644]
meta/recipes-core/glibc/glibc_2.20.bb