]> code.ossystems Code Review - openembedded-core.git/commitdiff
unzip: actually apply CVE-2018-18384
authorRoss Burton <ross.burton@intel.com>
Fri, 9 Nov 2018 16:28:36 +0000 (16:28 +0000)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 24 Nov 2018 21:45:48 +0000 (21:45 +0000)
(From OE-Core rev: d8e1b7afc536f989e7e6efdab0998d54f26ad1f6)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-extended/unzip/unzip_6.0.bb

index a47491ea4ab52f1b5c79d4141f83b4879fd2bcec..f6a4cb627dc79b9596a6fc8d59681bf2c7637075 100644 (file)
@@ -21,6 +21,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/infozip/UnZip%206.x%20%28latest%29/UnZip%206.0/
        file://19-cve-2016-9844-zipinfo-buffer-overflow.patch \
        file://symlink.patch \
        file://0001-unzip-fix-CVE-2018-1000035.patch \
+       file://CVE-2018-18384.patch \
 "
 UPSTREAM_VERSION_UNKNOWN = "1"