From 5c89539edb17d01ffe82a1b2e7d092816003ecf3 Mon Sep 17 00:00:00 2001 From: Yi Zhao Date: Tue, 22 Aug 2017 08:58:35 +0800 Subject: tiff: Security fixes Fix CVE-2017-9147, CVE-2017-9936, CVE-2017-10668, CVE-2017-11335 References: https://nvd.nist.gov/vuln/detail/CVE-2017-9147 https://nvd.nist.gov/vuln/detail/CVE-2017-9936 https://nvd.nist.gov/vuln/detail/CVE-2017-10668 https://nvd.nist.gov/vuln/detail/CVE-2017-11335 Patches from: CVE-2017-9147: https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06 CVE-2017-9936: https://github.com/vadz/libtiff/commit/fe8d7165956b88df4837034a9161dc5fd20cf67a CVE-2017-10688: https://github.com/vadz/libtiff/commit/6173a57d39e04d68b139f8c1aa499a24dbe74ba1 CVE-2017-11355: https://github.com/vadz/libtiff/commit/69bfeec247899776b1b396651adb47436e5f1556 Signed-off-by: Yi Zhao Signed-off-by: Richard Purdie --- meta/recipes-multimedia/libtiff/tiff_4.0.8.bb | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'meta/recipes-multimedia/libtiff/tiff_4.0.8.bb') diff --git a/meta/recipes-multimedia/libtiff/tiff_4.0.8.bb b/meta/recipes-multimedia/libtiff/tiff_4.0.8.bb index 4a7aeccd23..c8ad5d5c06 100644 --- a/meta/recipes-multimedia/libtiff/tiff_4.0.8.bb +++ b/meta/recipes-multimedia/libtiff/tiff_4.0.8.bb @@ -6,6 +6,10 @@ CVE_PRODUCT = "libtiff" SRC_URI = "http://download.osgeo.org/libtiff/tiff-${PV}.tar.gz \ file://libtool2.patch \ + file://CVE-2017-9147.patch \ + file://CVE-2017-9936.patch \ + file://CVE-2017-10688.patch \ + file://CVE-2017-11335.patch \ " SRC_URI[md5sum] = "2a7d1c1318416ddf36d5f6fa4600069b" -- cgit 1.2.3-korg