diff options
author | Yue Tao <Yue.Tao@windriver.com> | 2017-08-15 02:55:23 -0700 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2017-09-11 22:15:51 +0100 |
commit | 649f78102222ec156d490968c13d3222379a1956 (patch) | |
tree | 0fe8a67fd688cf50ece4e68609b9c7fb0ed6f9f8 /oe-init-build-env | |
parent | 201fa8f6a10469886db6d48c3a3e91712382e561 (diff) | |
download | openembedded-core-contrib-649f78102222ec156d490968c13d3222379a1956.tar.gz |
libtasn1: CVE-2017-10790
The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes
a NULL pointer dereference and crash when reading crafted input that
triggers assignment of a NULL value within an asn1_node structure. It
may lead to a remote denial of service attack.
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-10790
http://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;
h=d8d805e1f2e6799bb2dff4871a8598dc83088a39
(From OE-Core rev: 6176151625c971de031e14c97601ffd75a29772f)
Signed-off-by: Yue Tao <Yue.Tao@windriver.com>
Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'oe-init-build-env')
0 files changed, 0 insertions, 0 deletions