From 3063ae3b14d2220fd54042c9a3869a2d44c48f84 Mon Sep 17 00:00:00 2001 From: "Mingde (Matthew) Zeng" Date: Wed, 15 Jul 2020 13:43:39 -0400 Subject: [PATCH] net-snmp, openjpeg: add proper CVE tags to patches Signed-off-by: Mingde (Matthew) Zeng Signed-off-by: Khem Raj --- .../recipes-protocols/net-snmp/net-snmp/CVE-2019-20892.patch | 4 +++- .../recipes-graphics/openjpeg/openjpeg/CVE-2020-6851.patch | 4 ++++ .../recipes-graphics/openjpeg/openjpeg/CVE-2020-8112.patch | 4 ++++ 3 files changed, 11 insertions(+), 1 deletion(-) diff --git a/meta-networking/recipes-protocols/net-snmp/net-snmp/CVE-2019-20892.patch b/meta-networking/recipes-protocols/net-snmp/net-snmp/CVE-2019-20892.patch index 3e2637eaa5..ec1b6de8fc 100644 --- a/meta-networking/recipes-protocols/net-snmp/net-snmp/CVE-2019-20892.patch +++ b/meta-networking/recipes-protocols/net-snmp/net-snmp/CVE-2019-20892.patch @@ -8,9 +8,11 @@ This patch fixes https://sourceforge.net/p/net-snmp/bugs/2956/. Upstream-Status: Backport [ak: fixup for 5.8 context, changes to library/snmpusm.h] -CVE:CVE-2019-20892 + +CVE: CVE-2019-20892 Signed-off-by: Armin Kuster +Signed-off-by: Mingde (Matthew) Zeng --- snmplib/snmp_client.c | 22 +++---------- diff --git a/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-6851.patch b/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-6851.patch index 9f2fc901f9..1e14149c85 100644 --- a/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-6851.patch +++ b/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-6851.patch @@ -4,6 +4,10 @@ Date: Sat, 11 Jan 2020 01:51:19 +0100 Subject: [PATCH] opj_j2k_update_image_dimensions(): reject images whose coordinates are beyond INT_MAX (fixes #1228) +CVE: CVE-2020-6851 + +Signed-off-by: Mingde (Matthew) Zeng + --- src/lib/openjp2/j2k.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-8112.patch b/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-8112.patch index cb250530ef..6158601af0 100644 --- a/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-8112.patch +++ b/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2020-8112.patch @@ -6,6 +6,10 @@ Subject: [PATCH] opj_tcd_init_tile(): avoid integer overflow That could lead to later assertion failures. Fixes #1231 / CVE-2020-8112 + +CVE: CVE-2020-8112 + +Signed-off-by: Mingde (Matthew) Zeng --- src/lib/openjp2/tcd.c | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-)