From ccbef3848d749228a7947550f7712b872cff319f Mon Sep 17 00:00:00 2001 From: Tanu Kaskinen Date: Sat, 31 Mar 2018 08:24:27 +0300 Subject: libvorbis: CVE-2017-14632 Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184. References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14632 (From OE-Core rev: 6dcd8bdd5ffebafec5bbb811243f4dbf3a7038b8) Signed-off-by: Tanu Kaskinen Signed-off-by: Richard Purdie Signed-off-by: Armin Kuster --- meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb | 1 + 1 file changed, 1 insertion(+) (limited to 'meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb') diff --git a/meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb b/meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb index 75c2038800..11e1de7223 100644 --- a/meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb +++ b/meta/recipes-multimedia/libvorbis/libvorbis_1.3.5.bb @@ -12,6 +12,7 @@ DEPENDS = "libogg" SRC_URI = "http://downloads.xiph.org/releases/vorbis/${BP}.tar.xz \ file://CVE-2017-14633.patch \ + file://CVE-2017-14632.patch \ " SRC_URI[md5sum] = "28cb28097c07a735d6af56e598e1c90f" SRC_URI[sha256sum] = "54f94a9527ff0a88477be0a71c0bab09a4c3febe0ed878b24824906cd4b0e1d1" -- cgit 1.2.3-korg