summaryrefslogtreecommitdiffstats
path: root/scripts/qemuimage-tests/toolchain/cvs
diff options
context:
space:
mode:
authoryanjun.zhu <yanjun.zhu@windriver.com>2012-11-30 19:41:23 +0800
committerRichard Purdie <richard.purdie@linuxfoundation.org>2012-12-13 15:21:42 +0000
commitcde4273308ba38da164b96cfaa5efc4e3d0081ac (patch)
tree9b898869da157190031627488f298369e4a2a74f /scripts/qemuimage-tests/toolchain/cvs
parentbbd2e8e5178d52d7632df4e0fd94dfbe0cd4c9a2 (diff)
downloadpoky-cde4273308ba38da164b96cfaa5efc4e3d0081ac.tar.gz
squashfs: fix for CVE-2012-4024
Reference:http://squashfs.git.sourceforge.net/git/gitweb.cgi?p= squashfs/squashfs;a=commit;h=19c38fba0be1ce949ab44310d7f49887576cc123 Fix potential stack overflow in get_component() where an individual pathname component in an extract file (specified on the command line or in an extract file) could exceed the 1024 byte sized targname allocated on the stack. Fix by dynamically allocating targname rather than storing it as a fixed size on the stack. [YOCTO #3513] (From OE-Core rev: a45ec682748b0d6e5bb21af04d205edb5ef1360e) Signed-off-by: yanjun.zhu <yanjun.zhu@windriver.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'scripts/qemuimage-tests/toolchain/cvs')
0 files changed, 0 insertions, 0 deletions