!67 Fix CVE-2022-3756
From: @peng2285 Reviewed-by: @small_leek Signed-off-by: @small_leek
This commit is contained in:
commit
faac12b544
30
CVE-2022-3756.patch
Normal file
30
CVE-2022-3756.patch
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
From be374cc6cd51906eaacc7a4f77c9ac37ea7c69c7 Mon Sep 17 00:00:00 2001
|
||||||
|
From: qz_cx <wangqingzheng@kylinos.cn>
|
||||||
|
Date: Mon, 31 Oct 2022 14:29:31 +0800
|
||||||
|
Subject: [PATCH] Avoid potential integer overflow.
|
||||||
|
|
||||||
|
Merge pull request #2347 from kevinbackhouse/quicktimevideo-size-calc
|
||||||
|
|
||||||
|
Avoid potential integer overflow in QuickTimeVideo::userDataDecoder
|
||||||
|
@kevinbackhouse
|
||||||
|
kevinbackhouse committed on 7 Sep
|
||||||
|
---
|
||||||
|
src/quicktimevideo.cpp | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/src/quicktimevideo.cpp b/src/quicktimevideo.cpp
|
||||||
|
index 335d884..9b80947 100644
|
||||||
|
--- a/src/quicktimevideo.cpp
|
||||||
|
+++ b/src/quicktimevideo.cpp
|
||||||
|
@@ -895,7 +895,7 @@ namespace Exiv2 {
|
||||||
|
|
||||||
|
tv = find(userDataReferencetags, Exiv2::toString( buf.pData_));
|
||||||
|
|
||||||
|
- if(size == 0 || (size - 12) <= 0)
|
||||||
|
+ if (size <= 12)
|
||||||
|
break;
|
||||||
|
|
||||||
|
else if(equalsQTimeTag(buf, "DcMD") || equalsQTimeTag(buf, "NCDT"))
|
||||||
|
--
|
||||||
|
2.33.0
|
||||||
|
|
||||||
@ -1,12 +1,13 @@
|
|||||||
Name: exiv2
|
Name: exiv2
|
||||||
Version: 0.27.5
|
Version: 0.27.5
|
||||||
Release: 2
|
Release: 3
|
||||||
Summary: Exif, IPTC and XMP metadata and the ICC Profile
|
Summary: Exif, IPTC and XMP metadata and the ICC Profile
|
||||||
License: GPLv2+
|
License: GPLv2+
|
||||||
URL: http://www.exiv2.org/
|
URL: http://www.exiv2.org/
|
||||||
Source0: https://github.com/Exiv2/exiv2/archive/refs/tags/v%{version}.tar.gz
|
Source0: https://github.com/Exiv2/exiv2/archive/refs/tags/v%{version}.tar.gz
|
||||||
|
Patch0001: CVE-2022-3755.patch
|
||||||
|
Patch0002: CVE-2022-3756.patch
|
||||||
|
|
||||||
Patch: CVE-2022-3755.patch
|
|
||||||
Provides: exiv2-libs
|
Provides: exiv2-libs
|
||||||
Obsoletes: exiv2-libs
|
Obsoletes: exiv2-libs
|
||||||
|
|
||||||
@ -75,6 +76,9 @@ test -x %{buildroot}%{_libdir}/libexiv2.so
|
|||||||
%{_pkgdocdir}/
|
%{_pkgdocdir}/
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Thu Nov 10 2022 jiangpeng <jiangpeng01@ncti-gba.cn> - 0.27.5-3
|
||||||
|
- Fix CVE-2022-3756
|
||||||
|
|
||||||
* Sat Sep 17 2022 qz_cx <wangqingzheng@kylinos.cn> - 0.27.5-2
|
* Sat Sep 17 2022 qz_cx <wangqingzheng@kylinos.cn> - 0.27.5-2
|
||||||
- Type:CVE
|
- Type:CVE
|
||||||
- ID:NA
|
- ID:NA
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user