[OE-core] [dizzy] [PATCH 1/1] glibc: use patch for CVE-2015-1781

akuster808 akuster808 at gmail.com
Thu Dec 17 16:33:49 UTC 2015


merged to staging
git at git.yoctoproject.org/poky-contrib.git akuster/dizzy-next

thanks
Armin

On 11/26/2015 06:15 PM, Tudor Florea wrote:
> Patch added to the repo wasn't actually considered due to a
> erronously way of specifying the sources.
> 
> Signed-off-by: Tudor Florea <tudor.florea at enea.com>
> ---
>  meta/recipes-core/glibc/glibc_2.20.bb | 4 +---
>  1 file changed, 1 insertion(+), 3 deletions(-)
> 
> diff --git a/meta/recipes-core/glibc/glibc_2.20.bb b/meta/recipes-core/glibc/glibc_2.20.bb
> index a0736cd..2ab4083 100644
> --- a/meta/recipes-core/glibc/glibc_2.20.bb
> +++ b/meta/recipes-core/glibc/glibc_2.20.bb
> @@ -40,14 +40,12 @@ EGLIBCPATCHES = "\
>  #           file://eglibc-install-pic-archives.patch \
>  #	    file://initgroups_keys.patch \
>  #
> -CVEPATCHES = "\
> -        file://CVE-2015-1781-resolv-nss_dns-dns-host.c-buffer-overf.patch \
> -"
>  
>  CVEPATCHES = "\
>          file://CVE-2014-7817-wordexp-fails-to-honour-WRDE_NOCMD.patch \
>          file://CVE-2012-3406-Stack-overflow-in-vfprintf-BZ-16617.patch \
>          file://CVE-2014-9402_endless-loop-in-getaddr_r.patch \
> +        file://CVE-2015-1781-resolv-nss_dns-dns-host.c-buffer-overf.patch \
>      "
>  LIC_FILES_CHKSUM = "file://LICENSES;md5=e9a558e243b36d3209f380deb394b213 \
>        file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \
> 



More information about the Openembedded-core mailing list