diff options
| author | Yue Tao <Yue.Tao@windriver.com> | 2014-10-23 16:29:13 +0800 |
|---|---|---|
| committer | Martin Jansa <Martin.Jansa@gmail.com> | 2014-10-30 09:00:07 +0100 |
| commit | 81aecee0eda7600e6a6ae3f8264b2a1bc7a57f04 (patch) | |
| tree | da2bf948a00213669203dfe4272c2826ad24613b /meta-python/recipes-devtools/python/python-pyyaml | |
| parent | d47b4c7ca0f98071a6f33144630d6bf1b856ce18 (diff) | |
| download | meta-openembedded-81aecee0eda7600e6a6ae3f8264b2a1bc7a57f04.tar.gz | |
modphp: Security Advisory - php - CVE-2014-5120
gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before
5.5.16 does not ensure that pathnames lack %00 sequences, which might
allow remote attackers to overwrite arbitrary files via crafted input to
an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif,
(4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5120
Signed-off-by: Yue Tao <Yue.Tao@windriver.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python-pyyaml')
0 files changed, 0 insertions, 0 deletions
