nspr: Fix for CVE-2014-1545
authorXufeng Zhang <xufeng.zhang@windriver.com>
Thu, 24 Jul 2014 03:27:47 +0000 (23:27 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 25 Jul 2014 14:34:00 +0000 (15:34 +0100)
commite6b3e193d5d5ca95b365c42433a864fae17f730a
treef26012b25ae22dc435166e92025abe6850f8fe07
parentd82941da4d6e9b3c55bc0e7f38851c5c28f32cd3
nspr: Fix for CVE-2014-1545

Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote
attackers to execute arbitrary code or cause a denial of service
(out-of-bounds write) via vectors involving the sprintf and console
functions.Per: http://cwe.mitre.org/data/definitions/787.html

(From OE-Core rev: 191cab2f679491c2b6ddba49c5cf4886dcd22f57)

Signed-off-by: Xufeng Zhang <xufeng.zhang@windriver.com>
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-support/nspr/nspr/nspr-CVE-2014-1545.patch [new file with mode: 0644]
meta/recipes-support/nspr/nspr_4.10.3.bb