From 205d75ddb3b686eafa442a971247488c91950066 Mon Sep 17 00:00:00 2001 From: Joe Slater Date: Wed, 26 Sep 2018 15:51:25 -0700 Subject: libtiff: fix CVE-2017-17095 Backport fix from gitlab.com/libtiff/libtiff. nvd.nist.gov does not yet reference this patch. (From OE-Core rev: f72c8af3f2c1ec9e4d9ffcf0cc6e7fdf572b21b9) Signed-off-by: Joe Slater Signed-off-by: Ross Burton Signed-off-by: Richard Purdie --- .../libtiff/files/CVE-2017-17095.patch | 46 ++++++++++++++++++++++ meta/recipes-multimedia/libtiff/tiff_4.0.9.bb | 1 + 2 files changed, 47 insertions(+) create mode 100644 meta/recipes-multimedia/libtiff/files/CVE-2017-17095.patch (limited to 'meta/recipes-multimedia/libtiff') diff --git a/meta/recipes-multimedia/libtiff/files/CVE-2017-17095.patch b/meta/recipes-multimedia/libtiff/files/CVE-2017-17095.patch new file mode 100644 index 0000000000..9b9962ed35 --- /dev/null +++ b/meta/recipes-multimedia/libtiff/files/CVE-2017-17095.patch @@ -0,0 +1,46 @@ +From 9171da596c88e6a2dadcab4a3a89dddd6e1b4655 Mon Sep 17 00:00:00 2001 +From: Nathan Baker +Date: Thu, 25 Jan 2018 21:28:15 +0000 +Subject: [PATCH] Add workaround to pal2rgb buffer overflow. + +CVE: CVE-2017-17095 + +Upstream-Status: Backport (unchanged) [gitlab.com/libtiff/libtiff/commit/9171da5...] + +Signed-off-by: Joe Slater