poky/meta/recipes-support/libxslt/files/CVE-2019-18197.patch
Joe Slater 58e85c5395 libxslt: fix CVE-2019-18197
Use patch from upstream after 1.1.33 release.

(From OE-Core rev: aa88f0f3b7f70ddc88f187c91860505b256aeda3)

Signed-off-by: Joe Slater <joe.slater@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2019-11-18 14:42:13 +00:00

34 lines
990 B
Diff

libxslt: fix CVE-2019-18197
Added after 1.1.33 release.
CVE: CVE-2019-18197
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxslt.git]
Signed-off-by: Joe Slater <joe.slater@windriver.com>
commit 2232473733b7313d67de8836ea3b29eec6e8e285
Author: Nick Wellnhofer <wellnhofer@aevum.de>
Date: Sat Aug 17 16:51:53 2019 +0200
Fix dangling pointer in xsltCopyText
xsltCopyText didn't reset ctxt->lasttext in some cases which could
lead to various memory errors in relation with CDATA sections in input
documents.
Found by OSS-Fuzz.
diff --git a/libxslt/transform.c b/libxslt/transform.c
index 95ebd07..d7ab0b6 100644
--- a/libxslt/transform.c
+++ b/libxslt/transform.c
@@ -1094,6 +1094,8 @@ xsltCopyText(xsltTransformContextPtr ctxt, xmlNodePtr target,
if ((copy->content = xmlStrdup(cur->content)) == NULL)
return NULL;
}
+
+ ctxt->lasttext = NULL;
} else {
/*
* normal processing. keep counters to extend the text node