]> code.ossystems Code Review - openembedded-core.git/commit
pulseaudio: fix CVE-2014-3970
authorShan Hai <shan.hai@windriver.com>
Mon, 28 Jul 2014 05:18:50 +0000 (01:18 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 29 Jul 2014 08:56:44 +0000 (09:56 +0100)
commitf9d7407e54f1fa3d3a316a5bbb8b80665e6f03fd
tree148dcb8e68ff1c077ae5075aed097c00ea5ad2f8
parent5cba414e3fd7dbe761a6f628c6a368a412c0cba3
pulseaudio: fix CVE-2014-3970

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module
in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of
service (assertion failure and abort) via an empty UDP packet.

Fix it by picking a patch from pulseaudio upstream code.

Signed-off-by: Shan Hai <shan.hai@windriver.com>
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/pulseaudio/pulseaudio/CVE-2014-3970.patch [new file with mode: 0644]
meta/recipes-multimedia/pulseaudio/pulseaudio_5.0.bb