]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
libpng: whitelist CVE-2019-17371
authorRoss Burton <ross.burton@intel.com>
Mon, 4 Nov 2019 14:26:52 +0000 (14:26 +0000)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 5 Nov 2019 10:36:20 +0000 (10:36 +0000)
This is actually a memory leak in gif2png 2.x, so whitelist it in the libpng
recipe.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libpng/libpng_1.6.37.bb

index 66af2f3d60ed93dc645748f12afe0840a7c0a776..2ed87a843747c09917e291528c9eef0b195b04d8 100644 (file)
@@ -29,3 +29,6 @@ PACKAGES =+ "${PN}-tools"
 FILES_${PN}-tools = "${bindir}/png-fix-itxt ${bindir}/pngfix ${bindir}/pngcp"
 
 BBCLASSEXTEND = "native nativesdk"
+
+# CVE-2019-17371 is actually a memory leak in gif2png 2.x
+CVE_CHECK_WHITELIST += "CVE-2019-17371"