summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGyorgy Sarvari <skandigraun@gmail.com>2026-02-09 12:38:56 +0100
committerGyorgy Sarvari <skandigraun@gmail.com>2026-02-10 00:14:46 +0100
commit417d194dbecd3e45993f660694888914435bfbcd (patch)
treec996daa77ee37f01aa2cc5f2d432f813a079e2bb
parent15a5b7a6680aef2787904d645670d91442275f31 (diff)
downloadmeta-openembedded-417d194dbecd3e45993f660694888914435bfbcd.tar.gz
sox: mark CVE-2019-1010004 as patched
Details: https://nvd.nist.gov/vuln/detail/CVE-2019-1010004 The description mentions that this vulnerability overlaps with CVE-2017-18189, and Debian's investigation[1] confirms that it is solved by the same commit. Add the ID to the CVE tag of CVE-2017-18189.patch. [1]: https://security-tracker.debian.org/tracker/CVE-2019-1010004 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
-rw-r--r--meta-multimedia/recipes-multimedia/sox/sox/CVE-2017-18189.patch2
1 files changed, 1 insertions, 1 deletions
diff --git a/meta-multimedia/recipes-multimedia/sox/sox/CVE-2017-18189.patch b/meta-multimedia/recipes-multimedia/sox/sox/CVE-2017-18189.patch
index 3ca829b230..20af7cdada 100644
--- a/meta-multimedia/recipes-multimedia/sox/sox/CVE-2017-18189.patch
+++ b/meta-multimedia/recipes-multimedia/sox/sox/CVE-2017-18189.patch
@@ -8,7 +8,7 @@ into an infinite loop. Prevent this by sanity checking the channel
8count in open_read(). Also add an upper bound to prevent overflow 8count in open_read(). Also add an upper bound to prevent overflow
9in multiplication. 9in multiplication.
10 10
11CVE: CVE-2017-18189 11CVE: CVE-2017-18189 CVE-2019-1010004
12Upstream-Status: Backport [https://github.com/mansr/sox/commit/7a8ceb86212b28243bbb6d0de636f0dfbe833e53] 12Upstream-Status: Backport [https://github.com/mansr/sox/commit/7a8ceb86212b28243bbb6d0de636f0dfbe833e53]
13Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> 13Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
14--- 14---