aboutsummaryrefslogtreecommitdiffstats
path: root/meta/recipes-core/libxml/libxml2/libxml2-fix_NULL_pointer_derefs.patch
diff options
context:
space:
mode:
authorAndrej Valek <andrej.valek@siemens.com>2016-12-12 14:20:20 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2017-01-11 17:21:46 +0000
commit359189b6e6e5307156b08f0b7922a79e6acea1e2 (patch)
treec062758dc743378e45163d130e97b1435ff52cc9 /meta/recipes-core/libxml/libxml2/libxml2-fix_NULL_pointer_derefs.patch
parent5ba779d5abdbb8707ec6b346c76b798a6cd0d98f (diff)
downloadopenembedded-core-contrib-359189b6e6e5307156b08f0b7922a79e6acea1e2.tar.gz
libxml2: fix CVE-2016-4658 Disallow namespace nodes in XPointer points and ranges
Namespace nodes must be copied to avoid use-after-free errors. But they don't necessarily have a physical representation in a document, so simply disallow them in XPointer ranges. (From OE-Core rev: 00e928bd1c2aed9caeaf9e411743805d2139a023) (From OE-Core rev: cf810d5cc17cb6b9f53d21a404c89afe372accb7) Signed-off-by: Andrej Valek <andrej.valek@siemens.com> Signed-off-by: Pascal Bach <pascal.bach@siemens.com> Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Armin Kuster <akuster808@gmail.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-core/libxml/libxml2/libxml2-fix_NULL_pointer_derefs.patch')
0 files changed, 0 insertions, 0 deletions