]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commit
cairo: fix CVE-2018-19876 CVE-2019-6461 CVE-2019-6462
authorRoss Burton <ross.burton@intel.com>
Tue, 5 Mar 2019 23:38:15 +0000 (23:38 +0000)
committerArmin Kuster <akuster808@gmail.com>
Tue, 25 Jun 2019 14:26:36 +0000 (07:26 -0700)
commit8b5e68afc9767d8b6b966503e9353cadafae9bfb
tree500652f707be30415f0f9c551f8be4f14c1888b5
parent85541b9ae8cff770e2c20a9132c0867a25d190c2
cairo: fix CVE-2018-19876 CVE-2019-6461 CVE-2019-6462

Source: OpenEmbedded.org
MR: 97538, 97543
Type: Security Fix
Disposition: Backport from https://git.openembedded.org/openembedded-core/commit/meta/recipes-graphics/cairo?h=warrior&id=078e4d5c2114d942806cd0d5ad501805a011e841
ChangeID: fa8bdd44ad8613bb0679a1f6d9d670c3b47a0677
Description:

CVE-2018-19876 is a backport from upstream.

CVE-2019-6461 and CVE-2019-6462 are patches taken from Clear Linux.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
[Dropped CVE-2018-19876, not affected]
Issue was introduced in 1.15.8 by:
commit 721b7ea0a785afaa04b6da63f970c3c57666fdfe

Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-graphics/cairo/cairo/CVE-2019-6461.patch [new file with mode: 0644]
meta/recipes-graphics/cairo/cairo/CVE-2019-6462.patch [new file with mode: 0644]
meta/recipes-graphics/cairo/cairo_1.14.12.bb