]> code.ossystems Code Review - openembedded-core.git/commit
libvorbis: CVE-2018-5146
authorTanu Kaskinen <tanuk@iki.fi>
Sat, 31 Mar 2018 05:21:32 +0000 (08:21 +0300)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 31 Mar 2018 13:17:16 +0000 (14:17 +0100)
commit1b18cdf6b8bdb00ff5df165b9ac7bc2b10c87d57
tree54173fe567b7690d204a53f29c6e13bf06902e1b
parenta2b4718b5db8f220c89d71fbea4e3418be20731e
libvorbis: CVE-2018-5146

Prevent out-of-bounds write in codebook decoding. The bug could allow
code execution from a specially crafted Ogg Vorbis file.

References:
https://www.debian.org/security/2018/dsa-4140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146

Signed-off-by: Tanu Kaskinen <tanuk@iki.fi>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libvorbis/libvorbis/CVE-2018-5146.patch [new file with mode: 0644]
meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb