diff options
| author | Sona Sarmadi <sona.sarmadi@enea.com> | 2017-08-18 13:24:04 +0200 |
|---|---|---|
| committer | Adrian Dudau <adrian.dudau@enea.com> | 2017-08-21 10:55:46 +0200 |
| commit | 931b2732b5fb115a702bceb287cb9a3773f59877 (patch) | |
| tree | 3346824a700251bf859eee2b151bb474be6adf3d /recipes-core/libxml/libxml2/CVE-2017-5969.patch | |
| parent | 0ddff430004474009489094aa65e7679e26d35df (diff) | |
| download | meta-el-common-931b2732b5fb115a702bceb287cb9a3773f59877.tar.gz | |
gnutls: CVE-2017-7869
GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer
overflow and heap-based buffer overflow related to the cdk_pkt_read
function in opencdk/read-packet.c. This issue (which is a
subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.
This issue affects only applications which utilize the OpenPGP certificate
functionality of GnuTLS.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7869
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/51464af713d71802e3c6d5ac15f1a95132a354fe
Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Adrian Dudau <adrian.dudau@enea.com>
Diffstat (limited to 'recipes-core/libxml/libxml2/CVE-2017-5969.patch')
0 files changed, 0 insertions, 0 deletions
