<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-el-common.git/recipes-graphics, branch sumo</title>
<subtitle>Commmon distro layer for Enea Linux</subtitle>
<id>https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=sumo</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=sumo'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/'/>
<updated>2018-04-03T12:14:50+00:00</updated>
<entry>
<title>harfbuzz: fix error when cve-check-tool is enabled</title>
<updated>2018-04-03T12:14:50+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2018-03-22T12:28:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=e391ac7eb18379967c47e9444cc1313eb7dc4c98'/>
<id>urn:sha1:e391ac7eb18379967c47e9444cc1313eb7dc4c98</id>
<content type='text'>
When cve-check-tool is enabled, harfbuzz intermittently fails to build:
ERROR: harfbuzz-1.4.8-r0 do_configure: autoreconf execution failed.
This patch could solve this issue according to the mail conversation below:
https://www.mail-archive.com/yocto@yoctoproject.org/msg36472.html

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Martin Borg &lt;martin.borg@enea.com&gt;
</content>
</entry>
<entry>
<title>freetype/libarchive/gnutls: Drop CVE patches</title>
<updated>2018-03-01T09:42:05+00:00</updated>
<author>
<name>Martin Borg</name>
<email>martin.borg@enea.com</email>
</author>
<published>2018-03-01T09:39:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=b6d4cd74cebeded8a49c06c6d7a52c32769f3ed8'/>
<id>urn:sha1:b6d4cd74cebeded8a49c06c6d7a52c32769f3ed8</id>
<content type='text'>
The CVEs have been fixed in upstream poky/rocko.

Signed-off-by: Martin Borg &lt;martin.borg@enea.com&gt;
</content>
</entry>
<entry>
<title>freetype: fix for CVE-2017-8105</title>
<updated>2017-08-29T11:46:30+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-08-29T08:31:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=bf4d84df078cb19f1702f42a94c873026aa72e1d'/>
<id>urn:sha1:bf4d84df078cb19f1702f42a94c873026aa72e1d</id>
<content type='text'>
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based
buffer overflow related to the t1_decoder_parse_charstrings function in
psaux/t1decode.c.

References:
==========
https://security-tracker.debian.org/tracker/CVE-2017-8105
Upstream patch:
https://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f958c48ee431bef8d4d466b40c9cb2d4dbcb7791

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
</feed>
