<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-multimedia, branch warrior-21.0.3</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=warrior-21.0.3</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=warrior-21.0.3'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2020-01-16T22:38:52+00:00</updated>
<entry>
<title>libsndfile1: whitelist CVE-2018-13419</title>
<updated>2020-01-16T22:38:52+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-11-05T21:44:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=0931ac543124faf2fd536ba558c771ec1a065351'/>
<id>urn:sha1:0931ac543124faf2fd536ba558c771ec1a065351</id>
<content type='text'>
This is a memory leak that nobody else can replicate and has been rejected by
upstream.

(From OE-Core rev: 583990fc583a96dbf0655bff1630b2ebe199021d)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Adrian Bunk &lt;bunk@stusta.de&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libtiff: fix CVE-2019-17546</title>
<updated>2019-11-18T14:42:13+00:00</updated>
<author>
<name>Joe Slater</name>
<email>joe.slater@windriver.com</email>
</author>
<published>2019-11-06T18:45:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3b86def5ed2a07d765ce7530afd4b8d7af7cba15'/>
<id>urn:sha1:3b86def5ed2a07d765ce7530afd4b8d7af7cba15</id>
<content type='text'>
Apply unmodified patch from upstream.

(From OE-Core rev: 9cba3d02d00df23a3d0f830cb7d11752142f7d82)

Signed-off-by: Joe Slater &lt;joe.slater@windriver.com&gt;
Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: fix CVE-2019-14973</title>
<updated>2019-11-18T14:42:12+00:00</updated>
<author>
<name>Trevor Gamblin</name>
<email>trevor.gamblin@windriver.com</email>
</author>
<published>2019-09-20T18:25:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ee860651e9eefcc7f210c8f6147b118881be740f'/>
<id>urn:sha1:ee860651e9eefcc7f210c8f6147b118881be740f</id>
<content type='text'>
CVE reference: https://nvd.nist.gov/vuln/detail/CVE-2019-14973
Upstream merge: https://gitlab.com/libtiff/libtiff/commit/2218055c

(From OE-Core rev: cf26271c34fcbd76f90831955040020c3ee91b6b)

Signed-off-by: Trevor Gamblin &lt;trevor.gamblin@windriver.com&gt;
Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
[fixup for Warrior context]
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer1.0-vaapi: backport jpeg encode/decode fixes</title>
<updated>2019-09-30T15:44:41+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2019-07-25T04:03:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=6bf811e9bda84e12791328227b5834dd5ce83ce5'/>
<id>urn:sha1:6bf811e9bda84e12791328227b5834dd5ce83ce5</id>
<content type='text'>
Backport patches from 1.15 to fix JPEG encode/decode issues when
using VAAPI with Intel media-driver. See for details:

https://bugzilla.gnome.org/show_bug.cgi?id=796705
https://bugzilla.gnome.org/show_bug.cgi?id=796505

(From OE-Core rev: 507135276293287deed972d49feed511c21391a0)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: fix CVE-2019-7663</title>
<updated>2019-09-30T15:44:41+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-07-25T04:03:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=5ad2773072939151db51989733f94164f75a42a2'/>
<id>urn:sha1:5ad2773072939151db51989733f94164f75a42a2</id>
<content type='text'>
(From OE-Core rev: d06d6910d1ec9374bb15e02809e64e81198731b6)

(From OE-Core rev: 3c036ee32a8080c12a8c31abed6f0e989c06a306)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tiff: fix CVE-2019-6128</title>
<updated>2019-09-30T15:44:41+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-07-25T04:03:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7e2b96aae095cf32a1770c5f2ba2825677b08085'/>
<id>urn:sha1:7e2b96aae095cf32a1770c5f2ba2825677b08085</id>
<content type='text'>
(From OE-Core rev: 7293e417dd9bdd04fe0fec177a76c9286234ed46)

(From OE-Core rev: c4fcc2dfefb304ac59f8c49acaad149e239de260)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libid3tag: CVE-2017-11551 is the same as CVE-2004-2779</title>
<updated>2019-09-30T15:44:41+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-07-25T04:03:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=1fc478aa88f6156a68344562c3db9542f1b4b2a2'/>
<id>urn:sha1:1fc478aa88f6156a68344562c3db9542f1b4b2a2</id>
<content type='text'>
(From OE-Core rev: 0663e5f8f906803685f018061d51fd6277916e50)

(From OE-Core rev: 203439837077275d632a62050f6606bd203c2484)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libid3tag: handle unknown encodings (CVE-2017-11550)</title>
<updated>2019-09-30T15:44:41+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-07-25T04:03:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=93ba4bb6a1acb01ae20d99a5bf3c02060e766ee4'/>
<id>urn:sha1:93ba4bb6a1acb01ae20d99a5bf3c02060e766ee4</id>
<content type='text'>
(From OE-Core rev: 5090afc1b07e62f70ebcf63a7abb75b8552f0a52)

(From OE-Core rev: 9be34806ddfbe0e8d214290e0623f2b9779a14b7)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer1.0-plugins-base: fix CVE-2019-9928</title>
<updated>2019-07-29T22:50:49+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2019-07-26T04:47:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=1ccb3bd2dc39a8c0ab939364c4ffd58fdc683773'/>
<id>urn:sha1:1ccb3bd2dc39a8c0ab939364c4ffd58fdc683773</id>
<content type='text'>
(From OE-Core rev: ff6db726440e911358fc222ab21ee36a77004782)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>flac: also add flac to CVE_PRODUCT</title>
<updated>2019-05-20T13:38:16+00:00</updated>
<author>
<name>Chen Qi</name>
<email>Qi.Chen@windriver.com</email>
</author>
<published>2019-05-07T06:55:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=f94f7450fbccb366952f5e91525008beb021f304'/>
<id>urn:sha1:f94f7450fbccb366952f5e91525008beb021f304</id>
<content type='text'>
flac uses both 'flac' and 'libflac' as cve product.

(From OE-Core rev: dd1a74f6defa6fcd9cf79ec48c057a5ac7298624)

Signed-off-by: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
