]> code.ossystems Code Review - openembedded-core.git/commit
rsync: fix CVEs for included zlib
authorAnuj Mittal <anuj.mittal@intel.com>
Fri, 19 Jul 2019 01:31:06 +0000 (09:31 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 19 Jul 2019 15:16:31 +0000 (16:16 +0100)
commita55fbb4cb489853dfb0b4553f6e187c3f3633f48
treeb92722c04418decff48f2c66c9a6db0de34ffabd
parent5a38ef7eef9ecef2d27ae89f01691072bb94a25e
rsync: fix CVEs for included zlib

rsync includes its own copy of zlib and doesn't recommend linking with
the system version [1].

Import CVE fixes that impact zlib version 1.2.8 [2] that is currently used
by rsync.

[1] https://git.samba.org/rsync.git/?p=rsync.git;a=blob;f=zlib/README.rsync
[2] https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3a%2fa%3agnu%3azlib%3a1.2.8

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/rsync/files/CVE-2016-9840.patch [new file with mode: 0644]
meta/recipes-devtools/rsync/files/CVE-2016-9841.patch [new file with mode: 0644]
meta/recipes-devtools/rsync/files/CVE-2016-9842.patch [new file with mode: 0644]
meta/recipes-devtools/rsync/files/CVE-2016-9843.patch [new file with mode: 0644]
meta/recipes-devtools/rsync/rsync_3.1.3.bb