]> code.ossystems Code Review - openembedded-core.git/commit
bzip2: Fix CVE-2019-12900
authorSana Kazi <Sana.Kazi@kpit.com>
Tue, 4 Feb 2020 15:06:05 +0000 (07:06 -0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 4 Feb 2020 18:42:49 +0000 (18:42 +0000)
commitaec10c9993f04304466e15ea7a5bc4d85a357c5b
tree0ed0f87bc9d5ad1714fd01dea0e6787a49a5b26d
parentd00349526f5727fdff9b40c6139d95bd75af213d
bzip2: Fix CVE-2019-12900

Added patch for CVE-2019-12900 as backport from upstream.
Fixes out of bound access discovered while fuzzying karchive.

Tested by: Sana.Kazi@kpit.com

Signed-off-by: Saloni Jain <Saloni.Jain@kpit.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/bzip2/bzip2-1.0.6/CVE-2019-12900.patch [new file with mode: 0644]