Go to file
Peter Marko c7d64c7059 vorbis-tools: patch CVE-2023-43361
This is inactive project, so no official CVE fix will be available
anymore. That however does not mean that there is no fix available.
Following tries to prove that patch provided here is valid.

NVD CVE report [1] links issue [2] where this is reported.
Based on the report, fix was proposed in [3].
There was some review however the patch autor was not active.
[4] was later created trying to adddress the comments, but the project
was not active anymore. In this PR the patch was shrunk to a one-liner
in discussion.

I have tested the poc and it is real.
The patch fixes it, while not breaking the execution if good file path
is provided as argument.

[1] https://nvd.nist.gov/vuln/detail/CVE-2023-43361
[2] https://github.com/xiph/vorbis-tools/issues/41
[3] https://gitlab.xiph.org/xiph/vorbis-tools/-/merge_requests/7
[4] https://gitlab.xiph.org/xiph/vorbis-tools/-/merge_requests/8

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 67d94fecb0)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2025-02-04 14:29:37 -08:00
contrib contrib: oe-stylize: Use Python3 explicitly 2023-06-04 22:29:46 -07:00
meta-filesystems ntfs-3g-ntfsprogs: fix CVE-2023-52890 2025-01-16 09:17:32 -05:00
meta-gnome gimp: fix gimptool buildpaths errors 2025-01-16 09:17:32 -05:00
meta-initramfs meta-openemnedded: Add myself as styhead maintainer 2024-09-29 13:58:53 -07:00
meta-multimedia vorbis-tools: patch CVE-2023-43361 2025-02-04 14:29:37 -08:00
meta-networking wireshark: upgrade 4.2.8 -> 4.2.9 2025-01-16 09:17:32 -05:00
meta-oe audiofile: patch CVE-2017-6839 2025-02-04 14:29:37 -08:00
meta-perl libmodule-build-tiny-perl: fix QA Issue: TMPDIR [buildpaths] 2025-01-16 09:17:32 -05:00
meta-python python3-alembic: upgrade 1.13.2 -> 1.13.3 2024-11-25 13:29:59 -08:00
meta-webserver apache2: ignore disputed CVE CVE-2007-0086 2025-01-16 09:17:32 -05:00
meta-xfce xfce4-panel: upgrade 4.18.4 -> 4.18.5 2024-11-19 13:13:27 -08:00
.gitignore
COPYING.MIT
README.md meta-openemnedded: Add myself as styhead maintainer 2024-09-29 13:58:53 -07:00

Collection of layers for the OE-core universe

Main layer maintainer: Armin Kuster akuster808@gmail.com

This repository is a collection of layers to suppliment OE-Core with additional packages, Each layer have designated maintainer Please see the respective READMEs in the layer subdirectories