From: Steve Sakoman Date: Fri, 25 Mar 2022 17:11:50 +0000 (-1000) Subject: ghostscript: fix CVE-2020-15900 and CVE-2021-45949 for -native X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=da9b7b8973913c80c989aee1f5b34c98362725a8;p=thirdparty%2Fopenembedded%2Fopenembedded-core-contrib.git ghostscript: fix CVE-2020-15900 and CVE-2021-45949 for -native CVE patches (and the stack limits check patch) should have been added to SRC_URI_BASE so that they are applied for both target and -native packages. Signed-off-by: Steve Sakoman --- diff --git a/meta/recipes-extended/ghostscript/ghostscript_9.52.bb b/meta/recipes-extended/ghostscript/ghostscript_9.52.bb index ac3d0dca434..310c4f6d24d 100644 --- a/meta/recipes-extended/ghostscript/ghostscript_9.52.bb +++ b/meta/recipes-extended/ghostscript/ghostscript_9.52.bb @@ -33,14 +33,14 @@ SRC_URI_BASE = "https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/d file://do-not-check-local-libpng-source.patch \ file://avoid-host-contamination.patch \ file://mkdir-p.patch \ + file://CVE-2020-15900.patch \ + file://check-stack-limits-after-function-evalution.patch \ + file://CVE-2021-45949.patch \ " SRC_URI = "${SRC_URI_BASE} \ file://ghostscript-9.21-prevent_recompiling.patch \ file://cups-no-gcrypt.patch \ - file://CVE-2020-15900.patch \ - file://check-stack-limits-after-function-evalution.patch \ - file://CVE-2021-45949.patch \ " SRC_URI_class-native = "${SRC_URI_BASE} \