Browse Source

libvorbis: add patch for CVE-2017-14632 and CVE-2017-14633

Signed-off-by: Ted Hess <thess@kitschensync.net>
lilik-openwrt-22.03
Ted Hess 6 years ago
parent
commit
287cb874c2
2 changed files with 13 additions and 3 deletions
  1. +1
    -3
      libs/libvorbis/Makefile
  2. +12
    -0
      libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch

+ 1
- 3
libs/libvorbis/Makefile View File

@ -1,6 +1,4 @@
#
# Copyright (C) 2008-2015 OpenWrt.org
#
# This is free software, licensed under the GNU General Public License v2.
# See /LICENSE for more information.
#
@ -9,7 +7,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=libvorbis
PKG_VERSION:=1.3.5
PKG_RELEASE:=1
PKG_RELEASE:=2
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.xz
PKG_SOURCE_URL:=http://downloads.xiph.org/releases/vorbis/


+ 12
- 0
libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch View File

@ -0,0 +1,12 @@
--- a/lib/info.c
+++ b/lib/info.c
@@ -583,7 +583,8 @@ int vorbis_analysis_headerout(vorbis_dsp
oggpack_buffer opb;
private_state *b=v->backend_state;
- if(!b||vi->channels<=0){
+ if(!b||vi->channels<=0||vi->channels>255){
+ b = NULL;
ret=OV_EFAULT;
goto err_out;
}

Loading…
Cancel
Save