]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commit
libsndfile1: Fix CVE-2017-8361 and CVE-2017-8365
authorJackie Huang <jackie.huang@windriver.com>
Thu, 17 Aug 2017 06:44:27 +0000 (14:44 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 18 Aug 2017 22:46:37 +0000 (23:46 +0100)
commit768cd2beff0949bbe1bd07f2dc0d46ba105ca875
tree6b525afc62e6b2b33d058d09a8842e631dc1208b
parent0782f4fce2450fbeb40e351b49cc000b00b98aae
libsndfile1: Fix CVE-2017-8361 and CVE-2017-8365

Backport the patch to fix two CVEs:

CVE-2017-8361:
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows
remote attackers to cause a denial of service (buffer overflow and
application crash) or possibly have unspecified other impact via a
crafted audio file.

CVE-2017-8365:
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote
attackers to cause a denial of service (buffer over-read and application
crash) via a crafted audio file.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2017-8361
https://nvd.nist.gov/vuln/detail/CVE-2017-8365

(From OE-Core rev: d92877ade8fd4dd9b548c6b664bf4357a1f9428a)

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libsndfile/libsndfile1/CVE-2017-8361-8365.patch [new file with mode: 0644]
meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb