]> code.ossystems Code Review - openembedded-core.git/commit
libtiff: fix CVE-2013-4244
authorBaogen Shang <baogen.shang@windriver.com>
Fri, 28 Mar 2014 09:43:36 +0000 (17:43 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 28 Mar 2014 11:01:05 +0000 (11:01 +0000)
commit4eec8fae3f972a27bfb986066f5b3603599ebc25
tree75b2306a76989e57f6d4fb4d38833446a23778d8
parent355a8086637b859a469e1f2dc717b4ccec00b970
libtiff: fix CVE-2013-4244

cve description:
The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier
allows context-dependent attackers to cause a denial of service
(out-of-bounds write and crash) or possibly execute arbitrary code via
a crafted GIF image.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4244
Signed-off-by: Baogen Shang <baogen.shang@windriver.com>
Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libtiff/files/libtiff-CVE-2013-4244.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.0.3.bb