]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
unzip: Port debian fixes for two CVEs
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 24 Jun 2022 16:51:23 +0000 (17:51 +0100)
committerSteve Sakoman <steve@sakoman.com>
Tue, 28 Jun 2022 14:35:47 +0000 (04:35 -1000)
commit097469513f6dea7c678438e71a152f4e77fe670d
tree3fc9022ed96b12dc867cc7fcf89b24d8a5ac4b8f
parent357791da82f767ad695e4476aa12fea3d7db5e04
unzip: Port debian fixes for two CVEs

Add two fixes from debian for two CVEs. From:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1010355

I wans't able to get the reproducers to work but the added error
checking isn't probably a bad thing.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 054be00a632c2918dd1f973e76514e459fc6f017)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-extended/unzip/unzip/CVE-2022-0529.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip/CVE-2022-0530.patch [new file with mode: 0644]
meta/recipes-extended/unzip/unzip_6.0.bb