]> code.ossystems Code Review - openembedded-core.git/commit
flex: Backport buffer overflow fix
authorJussi Kukkonen <jussi.kukkonen@intel.com>
Mon, 10 Oct 2016 08:30:03 +0000 (11:30 +0300)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 11 Oct 2016 07:26:09 +0000 (08:26 +0100)
commit68d56306baa21e66756fb44c6c5680e725b1e3bc
tree3b066640b3be134551fb3152621d788ca02f40cd
parent591a5aecfe4a52dc3b9e11883334c604dd9fc957
flex: Backport buffer overflow fix

Fix a heap-based buffer overflow in yy_get_next_buffer()
(CVE-2016-6354).

Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/flex/flex/CVE-2016-6354.patch [new file with mode: 0644]
meta/recipes-devtools/flex/flex_2.6.0.bb