]> code.ossystems Code Review - openembedded-core.git/commit
tiff: Security fixes
authorYi Zhao <yi.zhao@windriver.com>
Tue, 22 Aug 2017 00:58:35 +0000 (08:58 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 11 Sep 2017 21:15:51 +0000 (22:15 +0100)
commiteaf72d105bed54e332e2e5c0c5c0a0087ecd91dd
treec73f09c9b17a9b323442d089f2a926fc9cab536d
parent649f78102222ec156d490968c13d3222379a1956
tiff: Security fixes

Fix CVE-2017-9147, CVE-2017-9936, CVE-2017-10668, CVE-2017-11335

References:
https://nvd.nist.gov/vuln/detail/CVE-2017-9147
https://nvd.nist.gov/vuln/detail/CVE-2017-9936
https://nvd.nist.gov/vuln/detail/CVE-2017-10668
https://nvd.nist.gov/vuln/detail/CVE-2017-11335

Patches from:
CVE-2017-9147:
https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06
CVE-2017-9936:
https://github.com/vadz/libtiff/commit/fe8d7165956b88df4837034a9161dc5fd20cf67a
CVE-2017-10688:
https://github.com/vadz/libtiff/commit/6173a57d39e04d68b139f8c1aa499a24dbe74ba1
CVE-2017-11355:
https://github.com/vadz/libtiff/commit/69bfeec247899776b1b396651adb47436e5f1556

(From OE-Core rev: 5c89539edb17d01ffe82a1b2e7d092816003ecf3)

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
minor fixes to get to apply

Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-multimedia/libtiff/files/CVE-2017-10688.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-11335.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9147.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/files/CVE-2017-9936.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.0.7.bb