]> code.ossystems Code Review - openembedded-core.git/commit
tiff: Security fixes
authorYi Zhao <yi.zhao@windriver.com>
Tue, 22 Aug 2017 00:58:35 +0000 (08:58 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 21 Nov 2017 14:42:53 +0000 (14:42 +0000)
commitdc7573cd330d1fc2e4bd50c1ba171906e1d5d5c0
treeeb70bb7de88d2fe746e82e90b803b875b9ce1ea3
parentd26ea3b9b698fcb059aaa34c2408e3b95ca4f31d
tiff: Security fixes

Fix CVE-2017-9147, CVE-2017-9936, CVE-2017-10668, CVE-2017-11335

References:
https://nvd.nist.gov/vuln/detail/CVE-2017-9147
https://nvd.nist.gov/vuln/detail/CVE-2017-9936
https://nvd.nist.gov/vuln/detail/CVE-2017-10668
https://nvd.nist.gov/vuln/detail/CVE-2017-11335

Patches from:
CVE-2017-9147:
https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06
CVE-2017-9936:
https://github.com/vadz/libtiff/commit/fe8d7165956b88df4837034a9161dc5fd20cf67a
CVE-2017-10688:
https://github.com/vadz/libtiff/commit/6173a57d39e04d68b139f8c1aa499a24dbe74ba1
CVE-2017-11355:
https://github.com/vadz/libtiff/commit/69bfeec247899776b1b396651adb47436e5f1556

(From OE-Core rev: 5c89539edb17d01ffe82a1b2e7d092816003ecf3)

(From OE-Core rev: eaf72d105bed54e332e2e5c0c5c0a0087ecd91dd)

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
minor fixes to get to apply

Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
meta/recipes-multimedia/libtiff/files/CVE-2017-10688.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-11335.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9147.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9936.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.0.7.bb