]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
flac: fix CVE-2020-22219
authorMichael Opdenacker <michael.opdenacker@bootlin.com>
Mon, 25 Sep 2023 14:00:53 +0000 (16:00 +0200)
committerSteve Sakoman <steve@sakoman.com>
Mon, 25 Sep 2023 17:03:13 +0000 (07:03 -1000)
commit87d92cb3d20c2686caddaa29cd17e18850ad9484
tree64de7eede8e80c842c21fcf58c655cb77330d089
parent532eb2c57fb1817999a857fc71db4438717ccadb
flac: fix CVE-2020-22219

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before
1.4.0 allows remote attackers to run arbitrary code via crafted input to
the encoder.

Signed-off-by: Meenali Gupta <meenali.gupta@windriver.com>
Signed-off-by: Michael Opdenacker <michael.opdenacker@bootlin.com>
Tested-by: Michael Opdenacker <michael.opdenacker@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-multimedia/flac/files/CVE-2020-22219.patch [new file with mode: 0644]
meta/recipes-multimedia/flac/flac_1.3.3.bb