Skip to content
Commit cd94ed01 authored by Zheng Qiu's avatar Zheng Qiu Committed by Richard Purdie
Browse files

tiff: fix CVE-2022-2953



While this does not happen with the tiff 4.3.0 release, it does happen with
the series of patches we have, so backport the two simple changes that
restrict the tiffcrop options to avoid the vulnerability.

CVE-2022-2953.patch was taken from upstream, and a small typo was fixed
for the CVE number. The other patch is included in tiff 4.4.0 but not
4.3.0, so add it as well.

Signed-off-by: default avatarRandy MacLeod <randy.macleod@windriver.com>
Signed-off-by: default avatarZheng Qiu <zheng.qiu@windriver.com>
Signed-off-by: default avatarSteve Sakoman <steve@sakoman.com>
Signed-off-by: default avatarRichard Purdie <richard.purdie@linuxfoundation.org>
parent 88e1917d
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment