generic-poky/meta
Li Wang cdb398935e cups - CVE-2011-2896
the patch come from:
http://cups.org/strfiles/3867/str3867.patch

The LZW decompressor in the LWZReadByte function in giftoppm.c
in the David Koblas GIF decoder in PBMPLUS, as used in the
gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7,
the LZWReadByte function in plug-ins/common/file-gif-load.c
in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c
in XPCE in SWI-Prolog 5.10.4 and earlier, and other products,
does not properly handle code words that are absent from the
decompression table when encountered, which allows remote attackers to
trigger an infinite loop or a heap-based buffer overflow, and possibly
execute arbitrary code, via a crafted compressed stream, a related
issue to CVE-2006-1168 and CVE-2011-2895.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2896

[YOCTO #3582]
[ CQID: WIND00299595 ]
Upstream-Status: Backport

(From OE-Core rev: 0742b7aecaada435f90f39f26914906a5eb1fd4f)

Signed-off-by: Li Wang <li.wang@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2012-12-17 17:24:56 +00:00
..
classes autotools: copy also remove-potcdate.sin from ${STAGING_DATADIR_NATIVE}/gettext/po 2012-12-17 17:24:55 +00:00
conf bitbake.conf/utils: Drop some OVERRIDES from FILESPATH 2012-12-11 15:58:36 +00:00
files bzip license: bzip2 not bzip. 2012-10-10 15:06:12 +01:00
lib/oe buildhistory_analysis: fix broken list length checks 2012-12-06 13:51:38 +00:00
recipes-bsp libacpi: Remove QA warning: No GNU_HASH in the elf binary 2012-12-13 15:18:47 +00:00
recipes-connectivity telepathy-glib: remove pkgconfig dependency in pkgconfig 2012-12-13 15:18:43 +00:00
recipes-core libxml2 CVE-2012-2871 2012-12-17 17:24:56 +00:00
recipes-devtools squashfs: fix CVE-2012-4025 2012-12-17 17:24:54 +00:00
recipes-extended cups - CVE-2011-2896 2012-12-17 17:24:56 +00:00
recipes-gnome librsvg: CVE-2011-3146 2012-12-17 17:24:56 +00:00
recipes-graphics mesa: remove dependency on mesa-dri in mesa-dri-dev 2012-12-17 17:24:55 +00:00
recipes-kernel linux-firmware: split out ralink drivers 2012-12-17 17:24:55 +00:00
recipes-lsb4/perl libdumpvalue-perl: Update to 1.17 2012-11-21 16:55:57 +00:00
recipes-multimedia libpng: enable nativesdk variant 2012-12-13 15:18:45 +00:00
recipes-qt nativesdk-qt4-tools: fix do_configure to be reentrant 2012-12-11 15:54:37 +00:00
recipes-rt rt-tests: added missing dependencies in Makefile 2012-12-07 17:28:21 +00:00
recipes-sato matchbox-keyboard: fix the build with libpng15 2012-12-13 15:18:45 +00:00
recipes-support libsoup: RRECOMMEND glib-networking 2012-12-14 17:15:49 +00:00
site site/common-linux: move ac_cv_o_nonblock_inherited to site/common-linux 2012-12-03 14:47:55 +00:00
COPYING.MIT
recipes.txt recipes.txt: Add entries for "recipes-rt" and "recipes-support" 2012-07-09 16:58:56 +01:00