]> code.ossystems Code Review - openembedded-core.git/commit
expat: CVE-2012-6702, CVE-2016-5300
authorSona Sarmadi <sona.sarmadi@enea.com>
Mon, 16 Jan 2017 06:30:00 +0000 (07:30 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 18 May 2017 12:13:38 +0000 (13:13 +0100)
commitc9a2e2f33e8b473f06a3941dab9b4ecccd111a23
tree78dc7c70657ab5aef2b57d7a2192df0cd62059b0
parent990db70dac60541ef14977177fff4361e31c51eb
expat: CVE-2012-6702, CVE-2016-5300

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5300
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6702
http://www.openwall.com/lists/oss-security/2016/06/04/5

Reference to upstream fix:
https://bugzilla.redhat.com/attachment.cgi?id=1165210
Squashed backport against vanilla Expat 2.1.1, addressing:
* CVE-2012-6702 -- unanticipated internal calls to srand
* CVE-2016-5300 -- use of too little entropy

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-core/expat/expat-2.1.0/CVE-2016-5300_CVE-2012-6702.patch [new file with mode: 0644]
meta/recipes-core/expat/expat_2.1.0.bb