mirror of
https://git.yoctoproject.org/poky
synced 2026-04-30 03:32:12 +02:00
tiff: add CVE tag to b258ed69a485a9cfb299d9f060eb2a46c54e5903.patch
* according to https://bugzilla.redhat.com/show_bug.cgi?id=2118863 this commit should be the fix for CVE-2022-2868 * resolves false-possitive entry in: https://lists.yoctoproject.org/g/yocto-security/message/705 CVE-2022-2868 (CVSS3: 8.1 HIGH): tiff https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2868 (From OE-Core rev: 97ad71541996023075950337e8b133c1a8551e0f) Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
38f46024d7
commit
6c79f0424b
@@ -5,11 +5,12 @@ Subject: [PATCH] Move the crop_width and crop_length computation after the
|
||||
sanity check to avoid warnings when built with
|
||||
-fsanitize=unsigned-integer-overflow.
|
||||
|
||||
Upstream-Status: Backport
|
||||
[https://gitlab.com/libtiff/libtiff/-/commit/b258ed69a485a9cfb299d9f060eb2a46c54e5903?merge_request_iid=294]
|
||||
Upstream-Status: Backport [https://gitlab.com/libtiff/libtiff/-/commit/b258ed69a485a9cfb299d9f060eb2a46c54e5903?merge_request_iid=294]
|
||||
|
||||
Signed-off-by: Teoh Jay Shen <jay.shen.teoh@intel.com>
|
||||
|
||||
CVE: CVE-2022-2868
|
||||
|
||||
---
|
||||
tools/tiffcrop.c | 5 ++---
|
||||
1 file changed, 2 insertions(+), 3 deletions(-)
|
||||
|
||||
Reference in New Issue
Block a user