]> code.ossystems Code Review - openembedded-core.git/commit
tiff: Security fixes
authorYi Zhao <yi.zhao@windriver.com>
Tue, 22 Aug 2017 00:58:35 +0000 (08:58 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 23 Aug 2017 07:44:41 +0000 (08:44 +0100)
commit5c89539edb17d01ffe82a1b2e7d092816003ecf3
tree5e459df5c228ea38985c14cb81d2f94008c86d6b
parent0724896f7a2092abf2f3bafa9fac96c5210d39a5
tiff: Security fixes

Fix CVE-2017-9147, CVE-2017-9936, CVE-2017-10668, CVE-2017-11335

References:
https://nvd.nist.gov/vuln/detail/CVE-2017-9147
https://nvd.nist.gov/vuln/detail/CVE-2017-9936
https://nvd.nist.gov/vuln/detail/CVE-2017-10668
https://nvd.nist.gov/vuln/detail/CVE-2017-11335

Patches from:
CVE-2017-9147:
https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06
CVE-2017-9936:
https://github.com/vadz/libtiff/commit/fe8d7165956b88df4837034a9161dc5fd20cf67a
CVE-2017-10688:
https://github.com/vadz/libtiff/commit/6173a57d39e04d68b139f8c1aa499a24dbe74ba1
CVE-2017-11355:
https://github.com/vadz/libtiff/commit/69bfeec247899776b1b396651adb47436e5f1556

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libtiff/files/CVE-2017-10688.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-11335.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9147.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9936.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.0.8.bb