]> code.ossystems Code Review - openembedded-core.git/commit
pulseaudio: fix CVE-2014-3970
authorShan Hai <shan.hai@windriver.com>
Mon, 28 Jul 2014 05:18:50 +0000 (01:18 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 10 Oct 2014 14:05:51 +0000 (15:05 +0100)
commitcf008bce23e897d1c3a51805af839af9241271df
treec7a967711da0db816d4a96ccc74cc42879ea9510
parent7e4f3f167c40c09bf2c32f5e366a8fad3c66b74b
pulseaudio: fix CVE-2014-3970

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module
in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of
service (assertion failure and abort) via an empty UDP packet.

Fix it by picking a patch from pulseaudio upstream code.

(From OE-Core rev: f9d7407e54f1fa3d3a316a5bbb8b80665e6f03fd)

Signed-off-by: Shan Hai <shan.hai@windriver.com>
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/pulseaudio/pulseaudio/CVE-2014-3970.patch [new file with mode: 0644]
meta/recipes-multimedia/pulseaudio/pulseaudio_5.0.bb