diff options
author | Yi Zhao <yi.zhao@windriver.com> | 2017-08-22 08:58:35 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2017-11-21 14:42:53 +0000 |
commit | dc7573cd330d1fc2e4bd50c1ba171906e1d5d5c0 (patch) | |
tree | eb70bb7de88d2fe746e82e90b803b875b9ce1ea3 /meta/recipes-multimedia/libtiff/tiff_4.0.7.bb | |
parent | d26ea3b9b698fcb059aaa34c2408e3b95ca4f31d (diff) | |
download | openembedded-core-dc7573cd330d1fc2e4bd50c1ba171906e1d5d5c0.tar.gz |
tiff: Security fixes
Fix CVE-2017-9147, CVE-2017-9936, CVE-2017-10668, CVE-2017-11335
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-9147
https://nvd.nist.gov/vuln/detail/CVE-2017-9936
https://nvd.nist.gov/vuln/detail/CVE-2017-10668
https://nvd.nist.gov/vuln/detail/CVE-2017-11335
Patches from:
CVE-2017-9147:
https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06
CVE-2017-9936:
https://github.com/vadz/libtiff/commit/fe8d7165956b88df4837034a9161dc5fd20cf67a
CVE-2017-10688:
https://github.com/vadz/libtiff/commit/6173a57d39e04d68b139f8c1aa499a24dbe74ba1
CVE-2017-11355:
https://github.com/vadz/libtiff/commit/69bfeec247899776b1b396651adb47436e5f1556
(From OE-Core rev: 5c89539edb17d01ffe82a1b2e7d092816003ecf3)
(From OE-Core rev: eaf72d105bed54e332e2e5c0c5c0a0087ecd91dd)
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
minor fixes to get to apply
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
Diffstat (limited to 'meta/recipes-multimedia/libtiff/tiff_4.0.7.bb')
-rw-r--r-- | meta/recipes-multimedia/libtiff/tiff_4.0.7.bb | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/meta/recipes-multimedia/libtiff/tiff_4.0.7.bb b/meta/recipes-multimedia/libtiff/tiff_4.0.7.bb index e58173604e..e60cbb564f 100644 --- a/meta/recipes-multimedia/libtiff/tiff_4.0.7.bb +++ b/meta/recipes-multimedia/libtiff/tiff_4.0.7.bb @@ -7,6 +7,10 @@ CVE_PRODUCT = "libtiff" SRC_URI = "http://download.osgeo.org/libtiff/tiff-${PV}.tar.gz \ file://libtool2.patch \ file://libtiff-CVE-2017-5225.patch \ + file://CVE-2017-9147.patch \ + file://CVE-2017-9936.patch \ + file://CVE-2017-10688.patch \ + file://CVE-2017-11335.patch \ " SRC_URI[md5sum] = "77ae928d2c6b7fb46a21c3a29325157b" |