From 287cb874c22f51d904840ed6f17ef9ccf814080b Mon Sep 17 00:00:00 2001 From: Ted Hess Date: Sat, 10 Feb 2018 09:34:54 -0500 Subject: [PATCH] libvorbis: add patch for CVE-2017-14632 and CVE-2017-14633 Signed-off-by: Ted Hess --- libs/libvorbis/Makefile | 4 +--- .../patches/100-CVE-2017-14632-CVE-2017-14633.patch | 12 ++++++++++++ 2 files changed, 13 insertions(+), 3 deletions(-) create mode 100644 libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch diff --git a/libs/libvorbis/Makefile b/libs/libvorbis/Makefile index 653f09100..550954e02 100644 --- a/libs/libvorbis/Makefile +++ b/libs/libvorbis/Makefile @@ -1,6 +1,4 @@ # -# Copyright (C) 2008-2015 OpenWrt.org -# # This is free software, licensed under the GNU General Public License v2. # See /LICENSE for more information. # @@ -9,7 +7,7 @@ include $(TOPDIR)/rules.mk PKG_NAME:=libvorbis PKG_VERSION:=1.3.5 -PKG_RELEASE:=1 +PKG_RELEASE:=2 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.xz PKG_SOURCE_URL:=http://downloads.xiph.org/releases/vorbis/ diff --git a/libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch b/libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch new file mode 100644 index 000000000..84601ff9b --- /dev/null +++ b/libs/libvorbis/patches/100-CVE-2017-14632-CVE-2017-14633.patch @@ -0,0 +1,12 @@ +--- a/lib/info.c ++++ b/lib/info.c +@@ -583,7 +583,8 @@ int vorbis_analysis_headerout(vorbis_dsp + oggpack_buffer opb; + private_state *b=v->backend_state; + +- if(!b||vi->channels<=0){ ++ if(!b||vi->channels<=0||vi->channels>255){ ++ b = NULL; + ret=OV_EFAULT; + goto err_out; + }