<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-multimedia, branch morty-next</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=morty-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=morty-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2018-04-04T10:06:56+00:00</updated>
<entry>
<title>libvorbis: CVE-2018-5146</title>
<updated>2018-04-04T10:06:56+00:00</updated>
<author>
<name>Tanu Kaskinen</name>
<email>tanuk@iki.fi</email>
</author>
<published>2018-03-31T05:24:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=6e9e5dddb1288b5af1bf5e443c859ddf8f38772b'/>
<id>urn:sha1:6e9e5dddb1288b5af1bf5e443c859ddf8f38772b</id>
<content type='text'>
Prevent out-of-bounds write in codebook decoding. The bug could allow
code execution from a specially crafted Ogg Vorbis file.

References:
https://www.debian.org/security/2018/dsa-4140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146

(From OE-Core rev: 7d5d262c03745e5c61e1e9c84f108d842d16e5ec)

Signed-off-by: Tanu Kaskinen &lt;tanuk@iki.fi&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libvorbis: CVE-2017-14632</title>
<updated>2018-04-04T10:06:56+00:00</updated>
<author>
<name>Tanu Kaskinen</name>
<email>tanuk@iki.fi</email>
</author>
<published>2018-03-31T05:24:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=272ceafc81d4b1828fb7eb2df82321317ab5beea'/>
<id>urn:sha1:272ceafc81d4b1828fb7eb2df82321317ab5beea</id>
<content type='text'>
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing
uninitialized memory in the function vorbis_analysis_headerout() in
info.c when vi-&gt;channels&lt;=0, a similar issue to Mozilla bug 550184.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14632

(From OE-Core rev: 6dcd8bdd5ffebafec5bbb811243f4dbf3a7038b8)

Signed-off-by: Tanu Kaskinen &lt;tanuk@iki.fi&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libvorbis: CVE-2017-14633</title>
<updated>2018-04-04T10:06:56+00:00</updated>
<author>
<name>Tanu Kaskinen</name>
<email>tanuk@iki.fi</email>
</author>
<published>2018-03-31T05:24:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7cb8bf848e77f24507e7bf212f20992ddd0c8f69'/>
<id>urn:sha1:7cb8bf848e77f24507e7bf212f20992ddd0c8f69</id>
<content type='text'>
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability
exists in the function mapping0_forward() in mapping0.c, which may lead
to DoS when operating on a crafted audio file with vorbis_analysis().

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14633

(From OE-Core rev: f398fb04549577922e6265c0969c6d6c35a11e7c)

Signed-off-by: Tanu Kaskinen &lt;tanuk@iki.fi&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7593</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:35:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=a5cbc746facf4529802b703a9731a8a6c4866a83'/>
<id>urn:sha1:a5cbc746facf4529802b703a9731a8a6c4866a83</id>
<content type='text'>
(From OE-Core rev: ff3904dec584daf627c267bf639d69aca13a1227)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7602</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:33:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c505c12a07b4240713c09b418be948d25d04a9ad'/>
<id>urn:sha1:c505c12a07b4240713c09b418be948d25d04a9ad</id>
<content type='text'>
(From OE-Core rev: 12325a8ebb5cab1837a6f6092eaa623a1a784eb6)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7601</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:31:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=9e658d2462fa766dc33f56c495656d365c4f5cd0'/>
<id>urn:sha1:9e658d2462fa766dc33f56c495656d365c4f5cd0</id>
<content type='text'>
(From OE-Core rev: ade8551d6a6810e87e83af72ea217aeca55c65c4)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7598</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:30:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=e963d34b7f5522e5a1d87352ea7c52c36b91e954'/>
<id>urn:sha1:e963d34b7f5522e5a1d87352ea7c52c36b91e954</id>
<content type='text'>
(From OE-Core rev: 7e367796d4bf97e299ee966b120f924de0f2bb04)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7596</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:28:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3c0fab47bc02e5c7b8cd506a08f9136728df4a24'/>
<id>urn:sha1:3c0fab47bc02e5c7b8cd506a08f9136728df4a24</id>
<content type='text'>
(From OE-Core rev: 94daee02cad9930d4ada648fd4bfdb63510643c0)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7595</title>
<updated>2017-11-21T14:43:54+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:27:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=dc293a78fc7770e4678f8d8e11d9da9f51990819'/>
<id>urn:sha1:dc293a78fc7770e4678f8d8e11d9da9f51990819</id>
<content type='text'>
(From OE-Core rev: 6536bfecb13b06765fdf6cb6fd70ce64f9077b8e)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: Security fix for CVE-2017-7594</title>
<updated>2017-11-21T14:43:53+00:00</updated>
<author>
<name>Rajkumar Veer</name>
<email>rveer@mvista.com</email>
</author>
<published>2017-11-04T05:25:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=f8db77f490f1c75770621c497549a00c5b8183cd'/>
<id>urn:sha1:f8db77f490f1c75770621c497549a00c5b8183cd</id>
<content type='text'>
(From OE-Core rev: 7bdb52d06a46ad659fc85db1992f9c6ab2fcf065)

Signed-off-by: Rajkumar Veer &lt;rveer@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
