From patchwork Mon Sep 30 04:47:03 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Armin Kuster X-Patchwork-Id: 174710 Delivered-To: patch@linaro.org Received: by 2002:a92:7e96:0:0:0:0:0 with SMTP id q22csp6648301ill; Sun, 29 Sep 2019 21:49:32 -0700 (PDT) X-Google-Smtp-Source: APXvYqwgLHnk+LmJaETefeTYlW+i0qLhd4aqmQAjuq80iHBbZJYRSIPmLKOitBJW/9ALunvGi0iy X-Received: by 2002:a17:90a:ab85:: with SMTP id n5mr24601433pjq.117.1569818972723; Sun, 29 Sep 2019 21:49:32 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1569818972; cv=none; d=google.com; s=arc-20160816; b=jfhn5tIz4YlnwXGWZDb4xlXQDPrDH2IWSTymjjKdpom2XH/Z8IEo9WXXwVz4GaVPQA J6sdvG+AzmeJ8VGFdPwnlk8iI0iadPT0kBL1dBH9UeTbnlt0A0eyx+0wBUNZzffJ1x5p QuA/TPMgUNqxWfHCVX86a9dSIZu98JXB050nKXj7uMAqSzO0Zobi5gxukOwq6DASGyEW 47wtT+fMm8jPOXcWiQcKbIp1Q272QtFuxW3p/Pv9FBxqGhXtsXorY+cK79GpnorQdSUR Csc/0nlqUBT6HTFBpeP8W/Q90Xw30e3q8A5bbCOLSk/3UMQzpVAkTFflCfGt8SXLLhrx 9gHw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:mime-version :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:references:in-reply-to:message-id:date :to:from:dkim-signature:delivered-to; bh=nKs4YIwZOUIpV8SfjeDKgom8cicln2RO4591jzg9lHg=; b=KmGLssymCdx28vpMZXkHqyNEDOSJO9RrDeYcHkhwZnl0coRvqTdf/6cC8LbfGCx7dk fENU12TUkLocSscgftgNfHtVww39hzYCYqAm3BYqtzrIHoegkM5ORrsYOO+5KlTzMiAu kQrfum/c9NZ0gGOZlhReltkD09fDDzfcA6Rk5kpgmMXkNO1m/cJqnATsQA05OWMhtUEk kIk11mBqC4UyjTpGH/7AknMMVZQqtVhcihTh75Rfc2rCgIRkh2wodADLvzwlO696Wi0v VTtymWqSvB3nNzDjG3EwmwC2dxqKDuyC3D1HeF1R5gqUcbcfTTz/C6RqWWJy35pUVLID il3w== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20161025 header.b=Kdafcl1W; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id b1si12637026pjo.4.2019.09.29.21.49.32; Sun, 29 Sep 2019 21:49:32 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20161025 header.b=Kdafcl1W; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 3ABAE7F382; Mon, 30 Sep 2019 04:48:44 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) by mail.openembedded.org (Postfix) with ESMTP id 678CA79CB3 for ; Mon, 30 Sep 2019 04:48:01 +0000 (UTC) Received: by mail-pf1-f179.google.com with SMTP id h195so4861767pfe.5 for ; Sun, 29 Sep 2019 21:48:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:message-id:in-reply-to:references; bh=hnT581ksGjvHz3tiL++Grc54cuBUBtoclFnz+7uX0dY=; b=Kdafcl1Wa1xOimBU8+B+2q8QbJ4ek7+6U5q1fvhX+qySJpcrJFMrpwlTVsTAfuLw3+ e8XBLnb+k5E3wxNTK9z69yavDQbjIeu0Of3c3Eaer8u/AUEWaPClXI453pDOAgqdBWFn ns/vvkE5iR6ryQrc1SdaTn2N01KtZu0Uc8FXb61XUdQJTYAJwjRtGR6ZECXH5bkzb1ET 4kcebOMFoPLyspUtLYuMn7dFxFOAMl5o1DnEThuZZ8I821iKr6DHLn+vVKxrd0Lor9F5 xu+hQDofXrGKp50UDRHoh6b39tvua9lffDjledqBPFkkgOsaFuRiiLM4NO+vbekNukoj HZpQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references; bh=hnT581ksGjvHz3tiL++Grc54cuBUBtoclFnz+7uX0dY=; b=WtUxNKm7P1IxJUc/Rn2LY2smmtFb7CVUw7dhdFRHxW908O5/+nYbfu0ZBGq0s6Gy49 AGjcBGN2SEZKn9FWChfYpu07bph6LNYKwUjhfgxmWJ05xP1BPPwxs194S4vauQ7IJ1Dn 59xR3Ve8oFhwm3Jwekzj3BBRQDdIJK/iAyn4nfIGYK2NBpWQroXa88pq265GkeYYxm1W NxFZtHaLX5NloLWZA4OthYOy9odF9QR7ot4nxzMDqFCTPvL+wkdu7DY5ceKMA8JMDuhT lKYG07vnQVKu5Lm+2Hv4zZ8RsEhODqmfg9SiO+odwbi4i9kCLHDqBiQO5YVD1MHLTA5N NNKA== X-Gm-Message-State: APjAAAVfr3O+LR3yRYRqC8+rlwTNkchYLssLO9RzqP5YPPoGuptrlIsl pySdkxXvGjEL1Z+TDes7+ZT6lsFxQ7g= X-Received: by 2002:a63:66c4:: with SMTP id a187mr22351890pgc.85.1569818882348; Sun, 29 Sep 2019 21:48:02 -0700 (PDT) Received: from akuster-ThinkPad-T460s.hsd1.ca.comcast.net ([2601:202:4180:a5c0:edf9:811d:ad92:85c2]) by smtp.gmail.com with ESMTPSA id h15sm18888493pgn.76.2019.09.29.21.48.01 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sun, 29 Sep 2019 21:48:01 -0700 (PDT) From: Armin Kuster To: openembedded-core@lists.openembedded.org Date: Sun, 29 Sep 2019 21:47:03 -0700 Message-Id: X-Mailer: git-send-email 2.7.4 In-Reply-To: References: Subject: [OE-core] [warrior-next 08/54] tiff: fix CVE-2019-6128 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton (From OE-Core rev: 7293e417dd9bdd04fe0fec177a76c9286234ed46) Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Armin Kuster --- .../libtiff/tiff/CVE-2019-6128.patch | 52 ++++++++++++++++++++++ meta/recipes-multimedia/libtiff/tiff_4.0.10.bb | 2 +- 2 files changed, 53 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-multimedia/libtiff/tiff/CVE-2019-6128.patch -- 2.7.4 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libtiff/tiff/CVE-2019-6128.patch b/meta/recipes-multimedia/libtiff/tiff/CVE-2019-6128.patch new file mode 100644 index 0000000..6f1fd4d --- /dev/null +++ b/meta/recipes-multimedia/libtiff/tiff/CVE-2019-6128.patch @@ -0,0 +1,52 @@ +CVE: CVE-2019-6128 +Upstream-Status: Backport +Signed-off-by: Ross Burton + +From 0c74a9f49b8d7a36b17b54a7428b3526d20f88a8 Mon Sep 17 00:00:00 2001 +From: Scott Gayou +Date: Wed, 23 Jan 2019 15:03:53 -0500 +Subject: [PATCH] Fix for simple memory leak that was assigned CVE-2019-6128. + +pal2rgb failed to free memory on a few errors. This was reported +here: http://bugzilla.maptools.org/show_bug.cgi?id=2836. +--- + tools/pal2rgb.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/tools/pal2rgb.c b/tools/pal2rgb.c +index 01d8502ec..9492f1cf1 100644 +--- a/tools/pal2rgb.c ++++ b/tools/pal2rgb.c +@@ -118,12 +118,14 @@ main(int argc, char* argv[]) + shortv != PHOTOMETRIC_PALETTE) { + fprintf(stderr, "%s: Expecting a palette image.\n", + argv[optind]); ++ (void) TIFFClose(in); + return (-1); + } + if (!TIFFGetField(in, TIFFTAG_COLORMAP, &rmap, &gmap, &bmap)) { + fprintf(stderr, + "%s: No colormap (not a valid palette image).\n", + argv[optind]); ++ (void) TIFFClose(in); + return (-1); + } + bitspersample = 0; +@@ -131,11 +133,14 @@ main(int argc, char* argv[]) + if (bitspersample != 8) { + fprintf(stderr, "%s: Sorry, can only handle 8-bit images.\n", + argv[optind]); ++ (void) TIFFClose(in); + return (-1); + } + out = TIFFOpen(argv[optind+1], "w"); +- if (out == NULL) ++ if (out == NULL) { ++ (void) TIFFClose(in); + return (-2); ++ } + cpTags(in, out); + TIFFGetField(in, TIFFTAG_IMAGEWIDTH, &imagewidth); + TIFFGetField(in, TIFFTAG_IMAGELENGTH, &imagelength); +-- +2.21.0 diff --git a/meta/recipes-multimedia/libtiff/tiff_4.0.10.bb b/meta/recipes-multimedia/libtiff/tiff_4.0.10.bb index 152fa81..a82d744 100644 --- a/meta/recipes-multimedia/libtiff/tiff_4.0.10.bb +++ b/meta/recipes-multimedia/libtiff/tiff_4.0.10.bb @@ -6,8 +6,8 @@ CVE_PRODUCT = "libtiff" SRC_URI = "http://download.osgeo.org/libtiff/tiff-${PV}.tar.gz \ file://libtool2.patch \ + file://CVE-2019-6128.patch" " - SRC_URI[md5sum] = "114192d7ebe537912a2b97408832e7fd" SRC_URI[sha256sum] = "2c52d11ccaf767457db0c46795d9c7d1a8d8f76f68b0b800a3dfe45786b996e4"