libtiff: fix CVE-2013-1961
authorMuzaffar Mahmood <muzaffar_mahmood@mentor.com>
Mon, 25 Aug 2014 11:51:06 +0000 (16:51 +0500)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 27 Aug 2014 11:12:32 +0000 (12:12 +0100)
commitd7638f26741e3eedfce45558521fd468ebc6a347
treef0baa2bca35a8cae2f7934d21819a8a00e1264f6
parente3a2af6ecfec1c4f3f1bb1653ced16c96bfda03f
libtiff: fix CVE-2013-1961

Integrate community fix for the issue CVE-2013-1961
and migrated to version 4.0.3.

Stack-based buffer overflow in the t2p_write_pdf_page function
in tiff2pdf in libtiff before 4.0.3 allows remote attackers to
cause a denial of service (application crash) via a crafted
image length and resolution in a TIFF image file.

(From OE-Core rev: f24e3456c60951d2985d7c23bdcc1f8c15d6c167)

Signed-off-by: Priyanka Shobhan <priyanka_shobhan@mentor.com>
Signed-off-by: Christopher Larson <chris_larson@mentor.com>
Signed-off-by: Muzaffar Mahmood <muzaffar_mahmood@mentor.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-multimedia/libtiff/files/libtiff-CVE-2013-1961.patch [new file with mode: 0644]
meta/recipes-multimedia/libtiff/tiff_4.0.3.bb