file: CVE-2014-9620 and CVE-2014-9621

CVE-2014-9620:
Limit the number of ELF notes processed - DoS
CVE-2014-9621:
Limit string printing to 100 chars - DoS

The patch comes from:
6ce24f35cd
0056ec3225
09e41625c9
af444af073
68bd8433c7
dddd3cdb95
445c8fb0eb
ce90e05774
65437cee25

[YOCTO #7178]

(From OE-Core rev: 0e4f0f893de2c0fac444b779b2b3028fd79e6048)

Signed-off-by: Chong Lu <Chong.Lu@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Chong.Lu@windriver.com 2015-01-26 09:56:05 +08:00 committed by Richard Purdie
parent 2a53df980d
commit 86da1430b7
2 changed files with 1415 additions and 0 deletions

File diff suppressed because it is too large Load Diff

View File

@ -13,6 +13,7 @@ DEPENDS_class-native = "zlib-native"
SRC_URI = "ftp://ftp.astron.com/pub/file/file-${PV}.tar.gz \
file://debian-742262.patch \
file://file-CVE-2014-9620-and-CVE-2014-9621.patch \
"
SRC_URI[md5sum] = "d420d8f2990cd344673acfbf8d76ff5a"