summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@intel.com>2019-11-06 17:37:56 +0200
committerRichard Purdie <richard.purdie@linuxfoundation.org>2019-11-07 19:47:27 +0000
commitdd06a288fa81aef25da8619c7503817d3059a98d (patch)
tree5de3f5e04460fbf053d581c4918a48264471e38f
parent26e1179507275a2440593bbf5ad2110175ab83a1 (diff)
downloadpoky-dd06a288fa81aef25da8619c7503817d3059a98d.tar.gz
libpng: whitelist CVE-2019-17371
This is actually a memory leak in gif2png 2.x, so whitelist it in the libpng recipe. (From OE-Core rev: 341e43ebd935daeb592cb073bf00f80c49a8ec2d) (From OE-Core rev: 581fa36d300fda00ae50c07b038fe847887f7ed3) Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Conflicts: meta/recipes-multimedia/libpng/libpng_1.6.37.bb
-rw-r--r--meta/recipes-multimedia/libpng/libpng_1.6.34.bb3
1 files changed, 3 insertions, 0 deletions
diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.34.bb b/meta/recipes-multimedia/libpng/libpng_1.6.34.bb
index 3877d6cbf0..2edf268396 100644
--- a/meta/recipes-multimedia/libpng/libpng_1.6.34.bb
+++ b/meta/recipes-multimedia/libpng/libpng_1.6.34.bb
@@ -30,3 +30,6 @@ PACKAGES =+ "${PN}-tools"
30FILES_${PN}-tools = "${bindir}/png-fix-itxt ${bindir}/pngfix ${bindir}/pngcp" 30FILES_${PN}-tools = "${bindir}/png-fix-itxt ${bindir}/pngfix ${bindir}/pngcp"
31 31
32BBCLASSEXTEND = "native nativesdk" 32BBCLASSEXTEND = "native nativesdk"
33
34# CVE-2019-17371 is actually a memory leak in gif2png 2.x
35CVE_CHECK_WHITELIST += "CVE-2019-17371"