diff options
author | Chee Yang Lee <chee.yang.lee@intel.com> | 2023-03-01 13:26:10 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2023-03-14 14:59:10 +0000 |
commit | c35692c6ebd704e7f4c13b34ac66eda35e8e251e (patch) | |
tree | bb310b55a3a4bb340fdc25da6a35fd33bfcdb297 /meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch | |
parent | 9fa2eba749289f49c7118d5c485257f820b705f3 (diff) | |
download | poky-c35692c6ebd704e7f4c13b34ac66eda35e8e251e.tar.gz |
tiff: fix multiple CVEs
import patches from debian
http://security.debian.org/debian-security/pool/updates/main/t/tiff/tiff_4.1.0+git191117-2~deb10u7.debian.tar.xz
fix multiple CVEs:
CVE-2022-3570
CVE-2022-3597
CVE-2022-3598
CVE-2022-3599
CVE-2022-3626
CVE-2022-3627
CVE-2022-3970
CVE-2022-48281
CVE-2023-0795
CVE-2023-0796
CVE-2023-0797
CVE-2023-0798
CVE-2023-0799
CVE-2023-0800
CVE-2023-0801
CVE-2023-0802
CVE-2023-0803
CVE-2023-0804
(From OE-Core rev: a6859c967e6e0079dd197fc36844b862938f4eed)
Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch')
-rw-r--r-- | meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch | 26 |
1 files changed, 26 insertions, 0 deletions
diff --git a/meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch b/meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch new file mode 100644 index 0000000000..5747202bd9 --- /dev/null +++ b/meta/recipes-multimedia/libtiff/files/CVE-2022-48281.patch | |||
@@ -0,0 +1,26 @@ | |||
1 | From 424c82b5b33256e7f03faace51dc8010f3ded9ff Mon Sep 17 00:00:00 2001 | ||
2 | From: Su Laus <sulau@freenet.de> | ||
3 | Date: Sat, 21 Jan 2023 15:58:10 +0000 | ||
4 | Subject: [PATCH] tiffcrop: Correct simple copy paste error. Fix #488. | ||
5 | |||
6 | Upstream-Status: Backport [import from debian http://security.debian.org/debian-security/pool/updates/main/t/tiff/tiff_4.1.0+git191117-2~deb10u7.debian.tar.xz] | ||
7 | CVE: CVE-2022-48281 | ||
8 | Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com> | ||
9 | |||
10 | --- | ||
11 | tools/tiffcrop.c | 2 +- | ||
12 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
13 | |||
14 | diff --git a/tools/tiffcrop.c b/tools/tiffcrop.c | ||
15 | index a0789a3..8aed9cd 100644 | ||
16 | --- a/tools/tiffcrop.c | ||
17 | +++ b/tools/tiffcrop.c | ||
18 | @@ -7564,7 +7564,7 @@ processCropSelections(struct image_data *image, struct crop_mask *crop, | ||
19 | crop_buff = (unsigned char *)_TIFFmalloc(cropsize + NUM_BUFF_OVERSIZE_BYTES); | ||
20 | else | ||
21 | { | ||
22 | - prev_cropsize = seg_buffs[0].size; | ||
23 | + prev_cropsize = seg_buffs[i].size; | ||
24 | if (prev_cropsize < cropsize) | ||
25 | { | ||
26 | next_buff = _TIFFrealloc(crop_buff, cropsize + NUM_BUFF_OVERSIZE_BYTES); | ||