diff options
| author | wangmy <wangmy@fujitsu.com> | 2021-05-18 16:03:28 +0800 |
|---|---|---|
| committer | Khem Raj <raj.khem@gmail.com> | 2021-05-19 09:17:49 -0700 |
| commit | 5be72693096cef671bf54bf1dd6ee8125614d064 (patch) | |
| tree | 31f225cb38b0ff606a5de869c338e79c07c8630d /meta-python/recipes-devtools/python/python-pygpgme/0003-handle-generic-error-when-no-passphrase-callback-pre.patch | |
| parent | bdf1be7c5511f3d19e4786b9f2bcad88dfb2a9e4 (diff) | |
| download | meta-openembedded-5be72693096cef671bf54bf1dd6ee8125614d064.tar.gz | |
exiv2: Fix CVE-2021-29457
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29457
The heap overflow is triggered when Exiv2 is used to write metadata into a crafted image file.
An attacker could potentially exploit the vulnerability to gain code execution, if they can
trick the victim into running Exiv2 on a crafted image file.
Upstream-Status: Accepted [https://github.com/Exiv2/exiv2/commit/0230620e6ea5e2da0911318e07ce6e66d1ebdf22]
CVE: CVE-2021-29457
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python-pygpgme/0003-handle-generic-error-when-no-passphrase-callback-pre.patch')
0 files changed, 0 insertions, 0 deletions
