mirror of
https://git.yoctoproject.org/poky
synced 2026-09-19 09:49:33 +02:00
affects: <= 1.1.14 CVE-2017-16612: Fix heap overflows when parsing malicious files It is possible to trigger heap overflows due to an integer overflow while parsing images and a signedness issue while parsing comments. The integer overflow occurs because the chosen limit 0x10000 for dimensions is too large for 32 bit systems, because each pixel takes 4 bytes. Properly chosen values allow an overflow which in turn will lead to less allocated memory than needed for subsequent reads. The signedness bug is triggered by reading the length of a comment as unsigned int, but casting it to int when calling the function XcursorCommentCreate. Turning length into a negative value allows the check against XCURSOR_COMMENT_MAX_LEN to pass, and the following addition of sizeof (XcursorComment) + 1 makes it possible to allocate less memory than needed for subsequent reads. (From OE-Core rev: bdf13518e79ab949c4320226a399ee4a3913ee30) Signed-off-by: Jagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com> Signed-off-by: Armin Kuster <akuster@mvista.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
25 lines
764 B
BlitzBasic
25 lines
764 B
BlitzBasic
SUMMARY = "Xcursor: X Cursor management library"
|
|
|
|
DESCRIPTION = "Xcursor is a simple library designed to help locate and \
|
|
load cursors. Cursors can be loaded from files or memory. A library of \
|
|
common cursors exists which map to the standard X cursor names. Cursors \
|
|
can exist in several sizes and the library automatically picks the best \
|
|
size."
|
|
|
|
require xorg-lib-common.inc
|
|
|
|
LICENSE = "MIT-style"
|
|
LIC_FILES_CHKSUM = "file://COPYING;md5=8902e6643f7bcd7793b23dcd5d8031a4"
|
|
|
|
DEPENDS += "libxrender libxfixes"
|
|
BBCLASSEXTEND = "native nativesdk"
|
|
|
|
PE = "1"
|
|
|
|
SRC_URI += "file://CVE-2017-16612.patch"
|
|
|
|
XORG_PN = "libXcursor"
|
|
|
|
SRC_URI[md5sum] = "1e7c17afbbce83e2215917047c57d1b3"
|
|
SRC_URI[sha256sum] = "9bc6acb21ca14da51bda5bc912c8955bc6e5e433f0ab00c5e8bef842596c33df"
|