mirror of
https://git.yoctoproject.org/poky
synced 2026-06-03 13:49:49 +00:00
ncurses: Fix for CVE-2021-39537
Add patch to fix CVE-2021-39537 Link: http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/Attic/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup (From OE-Core rev: abe9e7aec3b3363927eed014775145c55710fa07) Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com> Signed-off-by: Ranjitsinh Rathod <ranjitsinhrathod1991@gmail.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
0e5c82c4c9
commit
80132fb2df
@@ -0,0 +1,30 @@
|
|||||||
|
$NetBSD: patch-ncurses_tinfo_captoinfo.c,v 1.1 2021/10/09 07:52:36 wiz Exp $
|
||||||
|
|
||||||
|
Fix for CVE-2021-39537 from upstream:
|
||||||
|
https://github.com/ThomasDickey/ncurses-snapshots/commit/63ca9e061f4644795d6f3f559557f3e1ed8c738b#diff-7e95c7bc5f213e9be438e69a9d5d0f261a14952bcbd692f7b9014217b8047340
|
||||||
|
|
||||||
|
CVE: CVE-2021-39537
|
||||||
|
Upstream-Status: Backport [http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/Attic/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup]
|
||||||
|
Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com>
|
||||||
|
|
||||||
|
--- a/ncurses/tinfo/captoinfo.c 2020-02-02 23:34:34.000000000 +0000
|
||||||
|
+++ b/ncurses/tinfo/captoinfo.c
|
||||||
|
@@ -216,12 +216,15 @@ cvtchar(register const char *sp)
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case '^':
|
||||||
|
+ len = 2;
|
||||||
|
c = UChar(*++sp);
|
||||||
|
- if (c == '?')
|
||||||
|
+ if (c == '?') {
|
||||||
|
c = 127;
|
||||||
|
- else
|
||||||
|
+ } else if (c == '\0') {
|
||||||
|
+ len = 1;
|
||||||
|
+ } else {
|
||||||
|
c &= 0x1f;
|
||||||
|
- len = 2;
|
||||||
|
+ }
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
c = UChar(*sp);
|
||||||
@@ -3,6 +3,7 @@ require ncurses.inc
|
|||||||
SRC_URI += "file://0001-tic-hang.patch \
|
SRC_URI += "file://0001-tic-hang.patch \
|
||||||
file://0002-configure-reproducible.patch \
|
file://0002-configure-reproducible.patch \
|
||||||
file://0003-gen-pkgconfig.in-Do-not-include-LDFLAGS-in-generated.patch \
|
file://0003-gen-pkgconfig.in-Do-not-include-LDFLAGS-in-generated.patch \
|
||||||
|
file://CVE-2021-39537.patch \
|
||||||
"
|
"
|
||||||
# commit id corresponds to the revision in package version
|
# commit id corresponds to the revision in package version
|
||||||
SRCREV = "a669013cd5e9d6434e5301348ea51baf306c93c4"
|
SRCREV = "a669013cd5e9d6434e5301348ea51baf306c93c4"
|
||||||
|
|||||||
Reference in New Issue
Block a user