]> code.ossystems Code Review - openembedded-core.git/commit
connman: Fix for CVE-2017-12865
authorSona Sarmadi <sona.sarmadi@enea.com>
Mon, 21 Aug 2017 12:05:34 +0000 (14:05 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 23 Aug 2017 07:44:40 +0000 (08:44 +0100)
commitfb3e30e45eea2042fdb0b667cbc2c79ae3f5a1a9
tree7d90ecfc5f79e6037314b9abf28d8f861ab23361
parentf62d844424670967d2d40cd2afc96f5fc597bf1d
connman: Fix for CVE-2017-12865

dnsproxy: Fix crash on malformed DNS response
If the response query string is malformed, we might access memory
pass the end of "name" variable in parse_response().

[YOCTO #11959]

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/connman/connman/CVE-2017-12865.patch [new file with mode: 0644]
meta/recipes-connectivity/connman/connman_1.34.bb