summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/xz/xz_5.2.5.bb
diff options
context:
space:
mode:
authorRalph Siemsen <ralph.siemsen@linaro.org>2022-04-08 22:16:33 -0400
committerRichard Purdie <richard.purdie@linuxfoundation.org>2022-04-10 08:31:17 +0100
commit30eb28dd02920f166d2deaf5114a8e810c42b948 (patch)
treee7b6b09871d972e788f891f299b1c5be9f4ad929 /meta/recipes-extended/xz/xz_5.2.5.bb
parent89efab2850766378d89579c094670357775b69b6 (diff)
downloadpoky-30eb28dd02920f166d2deaf5114a8e810c42b948.tar.gz
xz: fix CVE-2022-1271
Malicious filenames can make xzgrep to write to arbitrary files or (with a GNU sed extension) lead to arbitrary code execution. Upstream-Status: Backport [https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch] CVE: CVE-2022-1271 (From OE-Core rev: 97bf86ccde4417daec8ef3945071a50a09134bc6) Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/xz/xz_5.2.5.bb')
-rw-r--r--meta/recipes-extended/xz/xz_5.2.5.bb4
1 files changed, 3 insertions, 1 deletions
diff --git a/meta/recipes-extended/xz/xz_5.2.5.bb b/meta/recipes-extended/xz/xz_5.2.5.bb
index 78aa6b20ca..720e070f4a 100644
--- a/meta/recipes-extended/xz/xz_5.2.5.bb
+++ b/meta/recipes-extended/xz/xz_5.2.5.bb
@@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=97d554a32881fee0aa283d96e47cb24a \
24 file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \ 24 file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \
25 " 25 "
26 26
27SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz" 27SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz \
28 file://CVE-2022-1271.patch \
29 "
28SRC_URI[md5sum] = "0d270c997aff29708c74d53f599ef717" 30SRC_URI[md5sum] = "0d270c997aff29708c74d53f599ef717"
29SRC_URI[sha256sum] = "f6f4910fd033078738bd82bfba4f49219d03b17eb0794eb91efbae419f4aba10" 31SRC_URI[sha256sum] = "f6f4910fd033078738bd82bfba4f49219d03b17eb0794eb91efbae419f4aba10"
30UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar" 32UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar"