summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/ghostscript/ghostscript
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@arm.com>2023-08-07 17:56:44 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2023-08-09 21:48:11 +0100
commit4adb1956198ff8d717b2175953762e5b17852eda (patch)
tree4ac16a6ef5e206108552728ab6e6108288b6fef5 /meta/recipes-extended/ghostscript/ghostscript
parent04a4bac6d2ff6a7b617865c567363798399b32cd (diff)
downloadpoky-4adb1956198ff8d717b2175953762e5b17852eda.tar.gz
ghostscript: backport fix for CVE-2023-38559
(From OE-Core rev: 38478a82598260e5e0616598e8cf78416dac1867) Signed-off-by: Ross Burton <ross.burton@arm.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/ghostscript/ghostscript')
-rw-r--r--meta/recipes-extended/ghostscript/ghostscript/0001-Bug-706897-Copy-pcx-buffer-overrun-fix-from-devices-.patch31
1 files changed, 31 insertions, 0 deletions
diff --git a/meta/recipes-extended/ghostscript/ghostscript/0001-Bug-706897-Copy-pcx-buffer-overrun-fix-from-devices-.patch b/meta/recipes-extended/ghostscript/ghostscript/0001-Bug-706897-Copy-pcx-buffer-overrun-fix-from-devices-.patch
new file mode 100644
index 0000000000..b29212fbc6
--- /dev/null
+++ b/meta/recipes-extended/ghostscript/ghostscript/0001-Bug-706897-Copy-pcx-buffer-overrun-fix-from-devices-.patch
@@ -0,0 +1,31 @@
1From d81b82c70bc1fb9991bb95f1201abb5dea55f57f Mon Sep 17 00:00:00 2001
2From: Chris Liddell <chris.liddell@artifex.com>
3Date: Mon, 17 Jul 2023 14:06:37 +0100
4Subject: [PATCH] Bug 706897: Copy pcx buffer overrun fix from
5 devices/gdevpcx.c
6
7Bounds check the buffer, before dereferencing the pointer.
8
9CVE: CVE-2023-38559
10Upstream-Status: Backport
11Signed-off-by: Ross Burton <ross.burton@arm.com>
12---
13 base/gdevdevn.c | 2 +-
14 1 file changed, 1 insertion(+), 1 deletion(-)
15
16diff --git a/base/gdevdevn.c b/base/gdevdevn.c
17index 7b14d9c71..6351fb77a 100644
18--- a/base/gdevdevn.c
19+++ b/base/gdevdevn.c
20@@ -1983,7 +1983,7 @@ devn_pcx_write_rle(const byte * from, const byte * end, int step, gp_file * file
21 byte data = *from;
22
23 from += step;
24- if (data != *from || from == end) {
25+ if (from >= end || data != *from) {
26 if (data >= 0xc0)
27 gp_fputc(0xc1, file);
28 } else {
29--
302.34.1
31