]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
xz: fix CVE-2022-1271
authorRalph Siemsen <ralph.siemsen@linaro.org>
Sat, 9 Apr 2022 02:16:33 +0000 (22:16 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 9 Apr 2022 21:51:12 +0000 (22:51 +0100)
commit97bf86ccde4417daec8ef3945071a50a09134bc6
tree721c287b796d8d45c626642145ebc1d5a538276d
parent9e2cb139fabf302fb85c292a8848d6fb66851d07
xz: fix CVE-2022-1271

Malicious filenames can make xzgrep to write to arbitrary files
or (with a GNU sed extension) lead to arbitrary code execution.

Upstream-Status: Backport [https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch]
CVE: CVE-2022-1271

Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/xz/xz/CVE-2022-1271.patch [new file with mode: 0644]
meta/recipes-extended/xz/xz_5.2.5.bb