summaryrefslogtreecommitdiffstats
path: root/meta-python/recipes-devtools/python/python-ldap
diff options
context:
space:
mode:
authorYue Tao <Yue.Tao@windriver.com>2014-10-23 16:29:13 +0800
committerMartin Jansa <Martin.Jansa@gmail.com>2014-10-30 09:00:07 +0100
commit81aecee0eda7600e6a6ae3f8264b2a1bc7a57f04 (patch)
treeda2bf948a00213669203dfe4272c2826ad24613b /meta-python/recipes-devtools/python/python-ldap
parentd47b4c7ca0f98071a6f33144630d6bf1b856ce18 (diff)
downloadmeta-openembedded-81aecee0eda7600e6a6ae3f8264b2a1bc7a57f04.tar.gz
modphp: Security Advisory - php - CVE-2014-5120
gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5120 Signed-off-by: Yue Tao <Yue.Tao@windriver.com> Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python-ldap')
0 files changed, 0 insertions, 0 deletions