]> code.ossystems Code Review - openembedded-core.git/commit
ghostscript: CVE-2017-9727, -9835, -11714
authorJoe Slater <jslater@windriver.com>
Tue, 22 Aug 2017 21:14:46 +0000 (14:14 -0700)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 11 Sep 2017 21:15:51 +0000 (22:15 +0100)
commit1c9e3318791e36d6bc851192a7640ee639f61f23
treea065ab259c6e4cd5222e29e23f3b7a1faac348b6
parent7fe1e9d46954f082af4debfa63cd982558dbf965
ghostscript: CVE-2017-9727, -9835, -11714

CVE-2017-9727: make bounds check in gx_ttfReader__Read more robust
CVE-2017-9835: bounds check the array allocations methods
CVE-2017-11714: prevent trying to reloc a freed object

(From OE-Core rev: 2eae91f9fa1cfdd3f0e6111956c8f193fd0db69f)

Signed-off-by: Joe Slater <jslater@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-extended/ghostscript/ghostscript/CVE-2017-11714.patch [new file with mode: 0644]
meta/recipes-extended/ghostscript/ghostscript/CVE-2017-9727.patch [new file with mode: 0644]
meta/recipes-extended/ghostscript/ghostscript/CVE-2017-9835.patch [new file with mode: 0644]
meta/recipes-extended/ghostscript/ghostscript_9.20.bb