]> code.ossystems Code Review - openembedded-core.git/commit
libarchive: CVE-2017-14503
authorJagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com>
Wed, 22 Aug 2018 13:19:59 +0000 (18:49 +0530)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 29 Aug 2018 14:22:26 +0000 (15:22 +0100)
commit3e000591928cfc35df192c7eb00db65687930566
tree5c6d8650b298221de08bd46fd04f9b37aefe43f2
parentbca64ae1b02717c04edfee6dcc9a89cfa91d0c73
libarchive: CVE-2017-14503

Reject LHA archive entries with negative size.

Affects libarchive = 3.3.2

Signed-off-by: Jagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-extended/libarchive/libarchive/CVE-2017-14503.patch [new file with mode: 0644]
meta/recipes-extended/libarchive/libarchive_3.3.2.bb