]> code.ossystems Code Review - openembedded-core.git/commit
libxml2: Fix CVE-2017-9047 and CVE-2017-9048
authorAndrej Valek <andrej.valek@siemens.com>
Wed, 14 Jun 2017 12:55:03 +0000 (14:55 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 27 Jul 2017 21:34:36 +0000 (22:34 +0100)
commitd549b8f3836b2ffda5c59a7ae4d955846c558646
tree1bdecc7b7dfae4cee55c168a0251b289ebb00871
parent41a5ea683cca3e635565a7a289ba260addfe4b11
libxml2: Fix CVE-2017-9047 and CVE-2017-9048

xmlSnprintfElementContent failed to correctly check the available
buffer space in two locations.

Fixes bug 781333 and bug 781701

CVE: CVE-2017-9047 CVE-2017-9048
(From OE-Core rev: bb0af023e811907b4e641b39f654ca921ac8794a)

Signed-off-by: Andrej Valek <andrej.valek@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-core/libxml/libxml2/libxml2-CVE-2017-9047_CVE-2017-9048.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2_2.9.4.bb