mirror of
https://git.yoctoproject.org/poky
synced 2026-09-29 07:36:20 +02:00
Add a patch to fix CVE-2022-43680 issue where use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations Link: https://nvd.nist.gov/vuln/detail/CVE-2022-43680 (From OE-Core rev: ac4476e6594417b14bfb05a110009ef245f419b0) Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
36 lines
1.3 KiB
BlitzBasic
36 lines
1.3 KiB
BlitzBasic
SUMMARY = "A stream-oriented XML parser library"
|
|
DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)"
|
|
HOMEPAGE = "https://github.com/libexpat/libexpat"
|
|
SECTION = "libs"
|
|
LICENSE = "MIT"
|
|
|
|
LIC_FILES_CHKSUM = "file://COPYING;md5=5b8620d98e49772d95fc1d291c26aa79"
|
|
|
|
SRC_URI = "git://github.com/libexpat/libexpat.git;protocol=https;branch=master \
|
|
file://CVE-2013-0340.patch \
|
|
file://CVE-2021-45960.patch \
|
|
file://CVE-2021-46143.patch \
|
|
file://CVE-2022-22822-27.patch \
|
|
file://CVE-2022-23852.patch \
|
|
file://CVE-2022-23990.patch \
|
|
file://CVE-2022-25235.patch \
|
|
file://CVE-2022-25236.patch \
|
|
file://CVE-2022-25313.patch \
|
|
file://CVE-2022-25313-regression.patch \
|
|
file://CVE-2022-25314.patch \
|
|
file://CVE-2022-25315.patch \
|
|
file://libtool-tag.patch \
|
|
file://CVE-2022-40674.patch \
|
|
file://CVE-2022-43680.patch \
|
|
"
|
|
|
|
SRCREV = "a7bc26b69768f7fb24f0c7976fae24b157b85b13"
|
|
|
|
inherit autotools lib_package
|
|
|
|
S = "${WORKDIR}/git/expat"
|
|
|
|
BBCLASSEXTEND = "native nativesdk"
|
|
|
|
CVE_PRODUCT = "expat libexpat"
|