mirror of
https://github.com/thead-yocto-mirror/meta-openembedded
synced 2026-09-16 12:12:16 +02:00
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29473
The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file.
An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2,
if they can trick the victim into running Exiv2 on a crafted image file.
Upstream-Status: Accepted [e6a0982f7c]
CVE: CVE-2021-29473
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit a9aecd2c32)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
24 lines
891 B
BlitzBasic
24 lines
891 B
BlitzBasic
SUMMARY = "Exif, Iptc and XMP metadata manipulation library and tools"
|
|
LICENSE = "GPLv2"
|
|
LIC_FILES_CHKSUM = "file://COPYING;md5=625f055f41728f84a8d7938acc35bdc2"
|
|
|
|
DEPENDS = "zlib expat"
|
|
|
|
SRC_URI = "https://exiv2.org/releases/${BPN}-${PV}-Source.tar.gz"
|
|
SRC_URI[sha256sum] = "a79f5613812aa21755d578a297874fb59a85101e793edc64ec2c6bd994e3e778"
|
|
|
|
# Once patch is obsolete (project should be aware due to PRs), dos2unix can be removed either
|
|
inherit dos2unix
|
|
SRC_URI += "file://0001-Use-compiler-fcf-protection-only-if-compiler-arch-su.patch \
|
|
file://CVE-2021-29457.patch \
|
|
file://CVE-2021-29458.patch \
|
|
file://CVE-2021-29463.patch \
|
|
file://CVE-2021-29464.patch \
|
|
file://CVE-2021-29470.patch \
|
|
file://CVE-2021-29473.patch \
|
|
file://CVE-2021-3482.patch"
|
|
|
|
S = "${WORKDIR}/${BPN}-${PV}-Source"
|
|
|
|
inherit cmake gettext
|