mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-04-02 02:49:12 +00:00
sox: mark CVE-2019-1010004 as patched
Details: https://nvd.nist.gov/vuln/detail/CVE-2019-1010004 The description mentions that this vulnerability overlaps with CVE-2017-18189, and Debian's investigation[1] confirms that it is solved by the same commit. Add the ID to the CVE tag of CVE-2017-18189.patch. [1]: https://security-tracker.debian.org/tracker/CVE-2019-1010004 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
This commit is contained in:
parent
15a5b7a668
commit
417d194dbe
@ -8,7 +8,7 @@ into an infinite loop. Prevent this by sanity checking the channel
|
||||
count in open_read(). Also add an upper bound to prevent overflow
|
||||
in multiplication.
|
||||
|
||||
CVE: CVE-2017-18189
|
||||
CVE: CVE-2017-18189 CVE-2019-1010004
|
||||
Upstream-Status: Backport [https://github.com/mansr/sox/commit/7a8ceb86212b28243bbb6d0de636f0dfbe833e53]
|
||||
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
|
||||
---
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user