mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-06-08 03:49:57 +00:00
zabbix: CVE-2020-15803 Security Advisory
References https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15803 Signed-off-by: Wang Mingyu <wangmy@cn.fujitsu.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
This commit is contained in:
@@ -0,0 +1,36 @@
|
|||||||
|
From 4943334fd9bf7dffd49f9e86251ad40b3efe2135 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Wang Mingyu <wangmy@cn.fujitsu.com>
|
||||||
|
Date: Fri, 11 Dec 2020 17:02:20 +0900
|
||||||
|
Subject: [PATCH] Fix bug for CVE-2020-15803
|
||||||
|
|
||||||
|
Signed-off-by: Wang Mingyu <wangmy@cn.fujitsu.com>
|
||||||
|
---
|
||||||
|
frontends/php/include/classes/html/CIFrame.php | 7 +++++++
|
||||||
|
1 file changed, 7 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/frontends/php/include/classes/html/CIFrame.php b/frontends/php/include/classes/html/CIFrame.php
|
||||||
|
index 32220cd..70f2ab5 100644
|
||||||
|
--- a/frontends/php/include/classes/html/CIFrame.php
|
||||||
|
+++ b/frontends/php/include/classes/html/CIFrame.php
|
||||||
|
@@ -29,6 +29,7 @@ class CIFrame extends CTag {
|
||||||
|
$this->setHeight($height);
|
||||||
|
$this->setScrolling($scrolling);
|
||||||
|
$this->setId($id);
|
||||||
|
+ $this->setSandbox();
|
||||||
|
}
|
||||||
|
|
||||||
|
public function setSrc($value = null) {
|
||||||
|
@@ -69,4 +70,10 @@ class CIFrame extends CTag {
|
||||||
|
$this->setAttribute('scrolling', $value);
|
||||||
|
return $this;
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+ private function setSandbox() {
|
||||||
|
+ if (ZBX_IFRAME_SANDBOX !== false) {
|
||||||
|
+ $this->setAttribute('sandbox', ZBX_IFRAME_SANDBOX);
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.25.1
|
||||||
|
|
||||||
@@ -26,6 +26,7 @@ PACKAGE_ARCH = "${MACHINE_ARCH}"
|
|||||||
SRC_URI = "http://jaist.dl.sourceforge.net/project/zabbix/ZABBIX%20Latest%20Stable/${PV}/${BPN}-${PV}.tar.gz \
|
SRC_URI = "http://jaist.dl.sourceforge.net/project/zabbix/ZABBIX%20Latest%20Stable/${PV}/${BPN}-${PV}.tar.gz \
|
||||||
file://0001-Fix-configure.ac.patch \
|
file://0001-Fix-configure.ac.patch \
|
||||||
file://zabbix-agent.service \
|
file://zabbix-agent.service \
|
||||||
|
file://CVE-2020-15803.patch \
|
||||||
"
|
"
|
||||||
|
|
||||||
SRC_URI[md5sum] = "e666539220be93b1af38e40f5fbb1f79"
|
SRC_URI[md5sum] = "e666539220be93b1af38e40f5fbb1f79"
|
||||||
|
|||||||
Reference in New Issue
Block a user