]> code.ossystems Code Review - openembedded-core.git/commit
unzip: fix four CVE defects
authorRoy Li <rongqing.li@windriver.com>
Tue, 23 Jun 2015 05:32:06 +0000 (13:32 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 8 Jul 2015 12:06:06 +0000 (13:06 +0100)
commit2bf9165f5db5edd946a064dc5e877f97817dbae0
tree0d4b73e69f41a6a4fd7d0d107fa0133a25ec32f8
parentc94ba6160d5965d4d2071154b43112eb87f4c898
unzip: fix four CVE defects

Port four patches from unzip_6.0-8+deb7u2.debian.tar.gz to fix:
     cve-2014-8139
     cve-2014-8140
     cve-2014-8141
     cve-2014-9636

Signed-off-by: Roy Li <rongqing.li@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-extended/unzip/unzip/09-cve-2014-8139-crc-overflow.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip/10-cve-2014-8140-test-compr-eb.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip/11-cve-2014-8141-getzip64data.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip/12-cve-2014-9636-test-compr-eb.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip_6.0.bb