Files
poky/meta/recipes-multimedia
Jagadeesh Krishnanjanappa 2128c21a0c libsndfile1: CVE-2017-14634
double64_init: Check psf->sf.channels against upper bound

This prevents division by zero later in the code.

While the trivial case to catch this (i.e. sf.channels < 1) has already
been covered, a crafted file may report a number of channels that is
so high (i.e. > INT_MAX/sizeof(double)) that it "somehow" gets
miscalculated to zero (if this makes sense) in the determination of the
blockwidth. Since we only support a limited number of channels anyway,
make sure to check here as well.

CVE-2017-14634

Closes: #318

Affects libsndfile1 = 1.0.28

(From OE-Core rev: eee93149a49274dc3deed7d89754ee4bda240575)

Signed-off-by: Jagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2018-08-23 07:50:01 +01:00
..
2018-08-07 12:13:03 +01:00
2018-08-07 12:13:02 +01:00
2018-08-23 07:50:00 +01:00
2018-08-09 23:47:55 +01:00
2018-05-04 13:28:05 +01:00
2017-11-30 10:49:21 +00:00
2018-08-23 07:50:00 +01:00
2018-08-23 07:50:01 +01:00
2018-07-26 13:16:40 +01:00
2018-08-16 22:40:28 +01:00
2018-05-04 13:28:05 +01:00
2017-11-21 13:06:11 +00:00
2017-07-06 14:38:15 +01:00
2018-05-08 16:14:14 +01:00