]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
xz: fix CVE-2022-1271
authorRalph Siemsen <ralph.siemsen@linaro.org>
Sat, 9 Apr 2022 02:17:15 +0000 (22:17 -0400)
committerSteve Sakoman <steve@sakoman.com>
Mon, 11 Apr 2022 14:08:00 +0000 (04:08 -1000)
commitda4180062f12aa855a0dd2c0dbe4f0721df67055
tree1516937a0f6cf31a43f334f3f832a218ff981c46
parent27385658aa552b287c4f8f4585f9c783db834123
xz: fix CVE-2022-1271

Malicious filenames can make xzgrep to write to arbitrary files
or (with a GNU sed extension) lead to arbitrary code execution.

Upstream-Status: Backport [https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch]
CVE: CVE-2022-1271

Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-extended/xz/xz/CVE-2022-1271.patch [new file with mode: 0644]
meta/recipes-extended/xz/xz_5.2.4.bb