]> code.ossystems Code Review - openembedded-core.git/commit
ghostscript: fix CVE-2021-45949
authorMinjae Kim <flowergom@gmail.com>
Mon, 28 Feb 2022 03:38:38 +0000 (11:38 +0800)
committerAnuj Mittal <anuj.mittal@intel.com>
Mon, 7 Mar 2022 07:39:05 +0000 (15:39 +0800)
commit9b0199a1d8ec3c7bbfd2022932d524d61f2c6832
tree1244762b45716dddb52e9f32cfcb2b7358903d92
parentedb6df08cb47a39918d28c709675d995c9e10031
ghostscript: fix CVE-2021-45949

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish
(called from sampled_data_continue and interp).

To apply this CVE-2021-45959 patch,
the check-stack-limits-after-function-evalution.patch should be applied first.

References:
https://nvd.nist.gov/vuln/detail/CVE-2021-45949

(From OE-Core rev: 5fb43ed64ae32abe4488f2eb37c1b82f97f83db0)

Signed-off-by: Minjae Kim <flowergom@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-extended/ghostscript/ghostscript/CVE-2021-45949.patch [new file with mode: 0644]
meta/recipes-extended/ghostscript/ghostscript/check-stack-limits-after-function-evalution.patch [new file with mode: 0644]
meta/recipes-extended/ghostscript/ghostscript_9.53.3.bb