]> code.ossystems Code Review - openembedded-core.git/commit
libvorbis: CVE-2018-5146
authorTanu Kaskinen <tanuk@iki.fi>
Tue, 20 Mar 2018 08:50:24 +0000 (10:50 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sun, 25 Mar 2018 08:33:35 +0000 (09:33 +0100)
commit1f01ce76c76d63f5ffe96baf518e670ae01c4d12
tree330438352dc7990bb592d86d3c86ac23a1f2a67a
parent5786e39e040f241f6bade29ba2ce61b7715e1b66
libvorbis: CVE-2018-5146

Prevent out-of-bounds write in codebook decoding. The bug could allow
code execution from a specially crafted Ogg Vorbis file.

References:
https://www.debian.org/security/2018/dsa-4140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146

Signed-off-by: Tanu Kaskinen <tanuk@iki.fi>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-multimedia/libvorbis/libvorbis/CVE-2018-5146.patch [new file with mode: 0644]
meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb