diff options
Diffstat (limited to 'meta/recipes-devtools/file/file/CVE-2019-8904.patch')
-rw-r--r-- | meta/recipes-devtools/file/file/CVE-2019-8904.patch | 30 |
1 files changed, 30 insertions, 0 deletions
diff --git a/meta/recipes-devtools/file/file/CVE-2019-8904.patch b/meta/recipes-devtools/file/file/CVE-2019-8904.patch new file mode 100644 index 0000000000..5c3d6f73a4 --- /dev/null +++ b/meta/recipes-devtools/file/file/CVE-2019-8904.patch | |||
@@ -0,0 +1,30 @@ | |||
1 | From 94b7501f48e134e77716e7ebefc73d6bbe72ba55 Mon Sep 17 00:00:00 2001 | ||
2 | From: Christos Zoulas <christos@zoulas.com> | ||
3 | Date: Mon, 18 Feb 2019 17:30:41 +0000 | ||
4 | Subject: [PATCH] PR/62: spinpx: Avoid non-nul-terminated string read. | ||
5 | |||
6 | Upstream-Status: Backport | ||
7 | CVE: CVE-2019-8904 | ||
8 | Affects < 5.36 | ||
9 | [Fixup for thud context] | ||
10 | Signed-off-by: Armin Kuster <akuster@mvista.com> | ||
11 | |||
12 | --- | ||
13 | src/readelf.c | 6 +++--- | ||
14 | 1 file changed, 3 insertions(+), 3 deletions(-) | ||
15 | |||
16 | Index: git/src/readelf.c | ||
17 | =================================================================== | ||
18 | --- git.orig/src/readelf.c | ||
19 | +++ git/src/readelf.c | ||
20 | @@ -558,8 +558,8 @@ do_bid_note(struct magic_set *ms, unsign | ||
21 | } | ||
22 | if (namesz == 4 && strcmp((char *)&nbuf[noff], "Go") == 0 && | ||
23 | type == NT_GO_BUILD_ID && descsz < 128) { | ||
24 | - if (file_printf(ms, ", Go BuildID=%s", | ||
25 | - (char *)&nbuf[doff]) == -1) | ||
26 | + if (file_printf(ms, ", Go BuildID=%.*s", | ||
27 | + CAST(int, descsz), CAST(char *, &nbuf[doff])) == -1) | ||
28 | return 1; | ||
29 | return 1; | ||
30 | } | ||