From: Anuj Mittal Date: Wed, 27 Nov 2019 00:53:24 +0000 (+0800) Subject: ghostscript: fix for CVE-2019-14811 is same as CVE-2019-14813 X-Git-Tag: uninative-2.8~960 X-Git-Url: https://code.ossystems.io/gitweb?a=commitdiff_plain;h=afef29326b4332fc87c53a5d9d43288cddcdd944;p=openembedded-core.git ghostscript: fix for CVE-2019-14811 is same as CVE-2019-14813 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14813 https://www.openwall.com/lists/oss-security/2019/08/28/2 Signed-off-by: Anuj Mittal Signed-off-by: Ross Burton --- diff --git a/meta/recipes-extended/ghostscript/ghostscript/CVE-2019-14811-0001.patch b/meta/recipes-extended/ghostscript/ghostscript/CVE-2019-14811-0001.patch index 3f28555e8a..d4ef0996ec 100644 --- a/meta/recipes-extended/ghostscript/ghostscript/CVE-2019-14811-0001.patch +++ b/meta/recipes-extended/ghostscript/ghostscript/CVE-2019-14811-0001.patch @@ -12,6 +12,7 @@ handler being used, but nevertheless, prevent access to .forceput from .setuserparams2. CVE: CVE-2019-14811 +CVE: CVE-2019-14813 Upstream-Status: Backport [git://git.ghostscript.com/ghostpdl.git] Signed-off-by: Stefan Ghinea