diff options
author | Chong.Lu@windriver.com <Chong.Lu@windriver.com> | 2015-01-26 09:56:05 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2015-02-11 17:39:49 +0000 |
commit | 0e4f0f893de2c0fac444b779b2b3028fd79e6048 (patch) | |
tree | f958acc3aa9c77d53633c95432e0d1961e51108b /meta/classes | |
parent | c45486fb91d53b427b93103392a470d169e39767 (diff) | |
download | openembedded-core-0e4f0f893de2c0fac444b779b2b3028fd79e6048.tar.gz openembedded-core-0e4f0f893de2c0fac444b779b2b3028fd79e6048.tar.bz2 openembedded-core-0e4f0f893de2c0fac444b779b2b3028fd79e6048.zip |
file: CVE-2014-9620 and CVE-2014-9621
CVE-2014-9620:
Limit the number of ELF notes processed - DoS
CVE-2014-9621:
Limit string printing to 100 chars - DoS
The patch comes from:
https://github.com/file/file/commit/6ce24f35cd4a43c4bdd249e8e0c4952c1f8eac67
https://github.com/file/file/commit/0056ec32255de1de973574b0300161a1568767d6
https://github.com/file/file/commit/09e41625c999a2e5b51e1092f0ef2432a99b5c33
https://github.com/file/file/commit/af444af0738468393f40f9d2261b1ea10fc4b2ba
https://github.com/file/file/commit/68bd8433c7e11a8dbe100deefdfac69138ee7cd9
https://github.com/file/file/commit/dddd3cdb95210a765dd90f7d722cb8b5534daee7
https://github.com/file/file/commit/445c8fb0ebff85195be94cd9f7e1df89cade5c7f
https://github.com/file/file/commit/ce90e05774dd77d86cfc8dfa6da57b32816841c4
https://github.com/file/file/commit/65437cee25199dbd385fb35901bc0011e164276c
[YOCTO #7178]
Signed-off-by: Chong Lu <Chong.Lu@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta/classes')
0 files changed, 0 insertions, 0 deletions