]> code.ossystems Code Review - openembedded-core.git/commit
libvorbis: CVE-2018-5146
authorTanu Kaskinen <tanuk@iki.fi>
Sat, 31 Mar 2018 05:21:32 +0000 (08:21 +0300)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 31 Mar 2018 13:17:22 +0000 (14:17 +0100)
commit5c880fe974907195c563b5580cb43b3b2fb92203
tree5cc9f72ba5d9c2c88ebe41cb33ce8ee969ef1da7
parente584aca38396db5e3d461f57804519261eecedc2
libvorbis: CVE-2018-5146

Prevent out-of-bounds write in codebook decoding. The bug could allow
code execution from a specially crafted Ogg Vorbis file.

References:
https://www.debian.org/security/2018/dsa-4140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146

Signed-off-by: Tanu Kaskinen <tanuk@iki.fi>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libvorbis/libvorbis/CVE-2018-5146.patch [new file with mode: 0644]
meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb