[OE-core] [poky][master][PATCH] Added patch for CVE-2019-12900 as backport from upstream.

2020-01-20 Thread Saloni Jain
From: Sana Kazi Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 36 ++ 1 file changed, 36 insertions(+) create mode 100644 meta/recipes

[OE-core] [poky][master][PATCH] bzip2: Fix CVE-2019-12900

2020-01-20 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 36 ++ 1 file changed

[OE-core] [poky][zeus][PATCH] bzip2: Fix CVE-2019-12900

2020-01-20 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 36 ++ 1 file changed

[OE-core] [poky][sumo][PATCH] bzip2: Fix CVE-2019-12900

2020-01-20 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 36 ++ meta/recipes

[OE-core] [meta-oe][sumo][PATCH] strongswan: avoid charon crash

2020-02-20 Thread Saloni Jain
) -> chunk_create_clone() -> memcpy() -> memcpy_noop(), it crashed with SIGBUS (frames 10, 9, 8). It could also be that chunk_map() has a bug which does not memmap() the full or correct areas. Upstream-Status: Pending Tested By: Anuj Chougule Signed-off-by: Anuj Chougule Signed-off-by:

[OE-core] [meta-oe][master][PATCH] strongswan: avoid charon crash

2020-02-20 Thread Saloni Jain
) -> chunk_create_clone() -> memcpy() -> memcpy_noop(), it crashed with SIGBUS (frames 10, 9, 8). It could also be that chunk_map() has a bug which does not memmap() the full or correct areas. Upstream-Status: Pending Tested By: Anuj Chougule Signed-off-by: Anuj Chougule Signed-off-by:

[OE-core] [poky][zeus][PATCH] bzip2: Fix CVE-2019-12900

2020-01-15 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 34 ++ 1 file changed

[OE-core] [poky][sumo][PATCH] bzip2: Fix CVE-2019-12900

2020-01-15 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 34 ++ meta/recipes

[OE-core] [poky][master][PATCH] bzip2: Fix CVE-2019-12900

2020-01-15 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 34 ++ 1 file changed

Re: [OE-core] [poky][zeus][PATCH] bzip2: Fix CVE-2019-12900

2020-01-15 Thread Saloni Jain
y 15, 2020 10:36 PM To: Saloni Jain Cc: openembedded-core@lists.openembedded.org ; Nisha Parrakat ; Sana Kazi Subject: Re: [poky][zeus][PATCH] bzip2: Fix CVE-2019-12900 On Wed, Jan 15, 2020 at 7:51 AM Saloni Jain wrote: > > From: Sana Kazi > > Added patch for CVE-2019-12900 as backpo

Re: [OE-core] [poky][master][PATCH] bzip2: Fix CVE-2019-12900

2020-01-17 Thread Saloni Jain
Sent: Wednesday, January 15, 2020 10:00 PM To: openembedded-core@lists.openembedded.org ; Saloni Jain Subject: Re: [OE-core] [poky][master][PATCH] bzip2: Fix CVE-2019-12900 On 15/01/2020 15:47, Saloni Jain wrote: > From: Sana Kazi > > Added patch for CVE-2019-12900 as backport from upstream

[OE-core] [poky][master][PATCH] bzip2: Fix CVE-2019-12900

2020-01-17 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 35 ++ 1 file changed

[OE-core] [poky][zeus][PATCH] bzip2: Fix CVE-2019-12900

2020-01-17 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 35 ++ 1 file changed

[OE-core] [poky][sumo][PATCH] bzip2: Fix CVE-2019-12900

2020-01-17 Thread Saloni Jain
From: Sana Kazi Added patch for CVE-2019-12900 as backport from upstream. Fixes out of bound access discovered while fuzzying karchive. Tested by: sana.k...@kpit.com Signed-off-by: Saloni Jain --- .../bzip2/bzip2-1.0.6/CVE-2019-12900.patch | 35 ++ meta/recipes

[OE-core] [poky][dunfell][PATCH] libxcrypt: Add fix for CVE-2021-33560

2021-09-13 Thread Saloni Jain
From: Saloni Jain Add fix for below CVE: CVE-2021-33560 Link: [https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=patch;h=3462280f2e23e16adf3ed5176e0f2413d8861320] Signed-off-by: Saloni Jain --- .../libgcrypt/files/CVE-2021-33560.patch | 108 ++ .../libgcrypt

[OE-core] [poky][dunfell][PATCH] db: Whitelist CVEs

2021-09-13 Thread Saloni Jain
From: Saloni Jain Below CVE affects only Oracle Berkeley DB as per upstream. Hence, whitelisted them. 1. CVE-2015-2583 Link: https://security-tracker.debian.org/tracker/CVE-2015-2583 2. CVE-2015-2624 Link: https://security-tracker.debian.org/tracker/CVE-2015-2624 3. CVE-2015-2626 Link: https

[OE-core] [poky][dunfell][PATCH] ffmpeg: Add fix for CVEs

2021-10-05 Thread Saloni Jain
From: Saloni Add fix for below CVE: CVE-2021-3566 Link: [http://git.videolan.org/?p=ffmpeg.git;a=patch;h=3bce9e9b3ea35c54ba793d7da99ea5157532] CVE-2021-38291 Link: [http://git.videolan.org/?p=ffmpeg.git;a=patch;h=e01d306c647b5827102260b885faa223b646d2d1] Signed-off-by: Saloni Jain