<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-multimedia, branch thud</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=thud</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=thud'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2019-07-29T22:50:43+00:00</updated>
<entry>
<title>gstreamer1.0-plugins-base: fix CVE-2019-9928</title>
<updated>2019-07-29T22:50:43+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2019-07-28T23:20:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=acd46a34c4642c3aba1ea50700110a3902cdafe6'/>
<id>urn:sha1:acd46a34c4642c3aba1ea50700110a3902cdafe6</id>
<content type='text'>
(From OE-Core rev: 276567b6a8e4b21dc978b352b5c715d6381867b1)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsndfile1: fix CVE-2019-3832</title>
<updated>2019-05-21T23:31:48+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-03-25T23:21:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3eb0322125b36571268a60e5a652746af79bfc2d'/>
<id>urn:sha1:3eb0322125b36571268a60e5a652746af79bfc2d</id>
<content type='text'>
The previous fix for CVE-2018-19758 wasn't complete, so backport another patch
to solve it properly.

(From OE-Core rev: 932762be3999906c2e8a0ed9236f1f01d9e2ea93)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsndfile1: update security patches</title>
<updated>2019-05-21T23:31:48+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-03-05T16:29:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c4d476508273b9c06ca6bcc42794107d59b56fba'/>
<id>urn:sha1:c4d476508273b9c06ca6bcc42794107d59b56fba</id>
<content type='text'>
Remove CVE-2017-14245-14246.patch, fix rejected upstream as it doesn't solve the
underlying issue.

Instead 0001-a-ulaw-fix-multiple-buffer-overflows-432 also solves CVE-2017-14245
and CVE-2017-14246 properly.

Add patches for CVE-2017-12562 and CVE-2018-19758.

Refresh CVE-2018-13139.patch.

(From OE-Core rev: e6b272b7c0d10f49dde71dd9714aaa0fb6aec091)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libpng: fix CVE-2019-7317</title>
<updated>2019-03-24T16:48:38+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-03-05T16:30:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=22febdc60ee903a89c96663e702920e027b9fab1'/>
<id>urn:sha1:22febdc60ee903a89c96663e702920e027b9fab1</id>
<content type='text'>
(From OE-Core rev: 983d4757db7d46dcd4116269c4446392e28f16fb)

(From OE-Core rev: ab4483fbd95fecb951e765ebc7da918b503142ca)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsndfile1: Security fix CVE-2018-19432</title>
<updated>2019-03-24T16:48:38+00:00</updated>
<author>
<name>Changqing Li</name>
<email>changqing.li@windriver.com</email>
</author>
<published>2019-02-20T08:54:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c707714cfe8d4f734ab88926a890ec768593ba5e'/>
<id>urn:sha1:c707714cfe8d4f734ab88926a890ec768593ba5e</id>
<content type='text'>
(From OE-Core rev: 6f010c9b7777aae5ce2108122d0c6d3b1d630a21)

(From OE-Core rev: 181d15b438ffa1d9da10399d33368906b464e4eb)

Signed-off-by: Changqing Li &lt;changqing.li@windriver.com&gt;
Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsndfile1: Security fix CVE-2017-17456/17457 CVE-2018-19661/19662</title>
<updated>2019-02-06T16:38:30+00:00</updated>
<author>
<name>Changqing Li</name>
<email>changqing.li@windriver.com</email>
</author>
<published>2019-01-07T08:06:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=4655904dbd6d4e2fe9e93400c8ace18bb135a85d'/>
<id>urn:sha1:4655904dbd6d4e2fe9e93400c8ace18bb135a85d</id>
<content type='text'>
fix 4 CVEs, which is backport from
https://github.com/erikd/libsndfile/commit/585cc28a93be27d6938f276af0011401b9f7c0ca

(From OE-Core rev: 8f4af329df5373db8910726a6b954652623003dd)

(From OE-Core rev: 1f3577fb6bacb09d2826c879a38d3d7d329cc39a)

Signed-off-by: Changqing Li &lt;changqing.li@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libpng: upgrade 1.6.35 -&gt; 1.6.36</title>
<updated>2019-02-06T16:38:30+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2018-12-19T07:29:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=1d9af235315d26500e6d9510b0cc1ca2a685bf89'/>
<id>urn:sha1:1d9af235315d26500e6d9510b0cc1ca2a685bf89</id>
<content type='text'>
For changes, see:

https://sourceforge.net/p/libpng/code/ci/libpng16/tree/CHANGES

License-Update: Added authors to license, formatting, version changes,
export classification clarification and a new libpng2 license with
clarification:

The new libpng license comprises the terms and conditions from the zlib
license, and the disclaimer from the Boost license. The legacy libpng
license license, used until libpng-1.6.35, is appended to the
new license, following the precedent established in the Python Software
Foundation License version 2.

(From OE-Core rev: 099aecfaa3baf6b24c2b751da92d7d2fa0266bf9)

(From OE-Core rev: 7c6e9f5447ff95755105088a3566989be4684250)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gst-validate: upgrade 1.14.2 -&gt; 1.14.4</title>
<updated>2019-01-08T20:14:43+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2018-11-27T08:55:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=68069654054ef603f7822007408a2429bc880d9f'/>
<id>urn:sha1:68069654054ef603f7822007408a2429bc880d9f</id>
<content type='text'>
(From OE-Core rev: 21387613fec1a8c142ed48d7a74d587e205b0c98)

(From OE-Core rev: 1d753f62d3e09cac92aadffc45992a04b95f0396)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer1.0-python: upgrade 1.14.3 -&gt; 1.14.4</title>
<updated>2019-01-08T20:14:43+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2018-11-27T08:55:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=aa22459112384fe5135ee693a354e7cb84d0c186'/>
<id>urn:sha1:aa22459112384fe5135ee693a354e7cb84d0c186</id>
<content type='text'>
(From OE-Core rev: 454129a0dc8eabb53753f9d416cf7271c796acf4)

(From OE-Core rev: 3f54c23c0ebed00de72d395c2718a6a86f13f3ef)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer1.0-omx: upgrade 1.14.3 -&gt; 1.14.4</title>
<updated>2019-01-08T20:14:43+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2018-11-27T08:55:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=499c3f1b18919c6d461d080b35592272829910ed'/>
<id>urn:sha1:499c3f1b18919c6d461d080b35592272829910ed</id>
<content type='text'>
(From OE-Core rev: 9b613f029490a3540492393206be004b649c0806)

(From OE-Core rev: 4f431f740186a2d5ab8cc0f592f6d8e908411637)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
