]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
tiff: fix CVE-2023-41175
authorYogita Urade <yogita.urade@windriver.com>
Fri, 15 Sep 2023 07:34:49 +0000 (07:34 +0000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 11 Oct 2023 19:11:10 +0000 (09:11 -1000)
commitb2518923dff885778c550f0faa22e99bf76b6288
treefac6046b07c31d3cf0b7b32788412174fd780821
parent3340e024ae8676081488f23a0678c28c23ab0b42
tiff: fix CVE-2023-41175

libtiff: potential integer overflow in raw2tiff.c

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2235264
https://security-tracker.debian.org/tracker/CVE-2023-41175
https://gitlab.com/libtiff/libtiff/-/issues/592

Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 4ee806cbc12fbc830b09ba6222e96b1e5f24539f)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-multimedia/libtiff/files/CVE-2023-41175.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.5.1.bb