]> code.ossystems Code Review - openembedded-core.git/commit
libvorbis: CVE-2018-5146 morty-next
authorTanu Kaskinen <tanuk@iki.fi>
Sat, 31 Mar 2018 05:24:28 +0000 (08:24 +0300)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 5 Apr 2018 14:11:17 +0000 (15:11 +0100)
commitccf97c35f6153abc639f01c4940dda5e6e8a3fbe
treea4916069bf15cedd6d2fd50cc249e17062277d03
parentccbef3848d749228a7947550f7712b872cff319f
libvorbis: CVE-2018-5146

Prevent out-of-bounds write in codebook decoding. The bug could allow
code execution from a specially crafted Ogg Vorbis file.

References:
https://www.debian.org/security/2018/dsa-4140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146

(From OE-Core rev: 7d5d262c03745e5c61e1e9c84f108d842d16e5ec)

Signed-off-by: Tanu Kaskinen <tanuk@iki.fi>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-multimedia/libvorbis/libvorbis/CVE-2018-5146.patch [new file with mode: 0644]
meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb