summaryrefslogtreecommitdiffstats
path: root/recipes-core/libxml/libxml2/CVE-2017-5969.patch
diff options
context:
space:
mode:
authorSona Sarmadi <sona.sarmadi@enea.com>2017-08-18 13:24:04 +0200
committerAdrian Dudau <adrian.dudau@enea.com>2017-08-21 10:55:46 +0200
commit931b2732b5fb115a702bceb287cb9a3773f59877 (patch)
tree3346824a700251bf859eee2b151bb474be6adf3d /recipes-core/libxml/libxml2/CVE-2017-5969.patch
parent0ddff430004474009489094aa65e7679e26d35df (diff)
downloadmeta-el-common-931b2732b5fb115a702bceb287cb9a3773f59877.tar.gz
gnutls: CVE-2017-7869
GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10. This issue affects only applications which utilize the OpenPGP certificate functionality of GnuTLS. References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7869 Upstream patch: https://gitlab.com/gnutls/gnutls/commit/51464af713d71802e3c6d5ac15f1a95132a354fe Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com> Signed-off-by: Adrian Dudau <adrian.dudau@enea.com>
Diffstat (limited to 'recipes-core/libxml/libxml2/CVE-2017-5969.patch')
0 files changed, 0 insertions, 0 deletions