mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-10-02 02:47:33 +00:00
Fix following CVEs for imagemagick: CVE-2021-20311, CVE-2021-20312, CVE-2021-20313 CVE-2021-20309, CVE-2021-20310, CVE-2021-3610 CVE-2022-0284, CVE-2022-2719 fix-cipher-leak.patch fixes CVE-2021-20311, CVE-2021-20312, CVE-2021-20313 Ignore following CVES as current version is not affected by them: CVE-2014-9826, CVE-2016-7538, CVE-2017-5506 Signed-off-by: Sana Kazi <sanakazi720@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
27 lines
984 B
Diff
27 lines
984 B
Diff
From 930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3 Mon Sep 17 00:00:00 2001
|
|
From: Cristy <mikayla-grace@urban-warrior.org>
|
|
Date: Thu, 27 May 2021 10:30:17 -0400
|
|
Subject: [PATCH] eliminate heap buffer overflow vulnerability, thanks to
|
|
ZhangJiaxing (@r0fm1a) from Codesafe Team of Legendsec at Qi'anxin Group
|
|
|
|
CVE: CVE-2021-3610
|
|
Upstream-Status: https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3.patch]
|
|
Signed-off-by: Sana Kazi Sana.Kazi@kpit.com
|
|
---
|
|
coders/tiff.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/coders/tiff.c b/coders/tiff.c
|
|
index 277b9788be5..b88ce368ba5 100644
|
|
--- a/coders/tiff.c
|
|
+++ b/coders/tiff.c
|
|
@@ -1894,7 +1894,7 @@ static Image *ReadTIFFImage(const ImageInfo *image_info,
|
|
/*
|
|
Convert stripped TIFF image.
|
|
*/
|
|
- extent=2*TIFFStripSize(tiff);
|
|
+ extent=4*TIFFStripSize(tiff);
|
|
#if defined(TIFF_VERSION_BIG)
|
|
extent+=image->columns*sizeof(uint64);
|
|
#else
|