* [OE-core][dunfell][PATCH] libwebp: Update CVE ID CVE-2023-4863
@ 2023-10-16 7:56 Pawan
2023-10-16 8:09 ` [dunfell][PATCH] " Pawan Badganchi
0 siblings, 1 reply; 2+ messages in thread
From: Pawan @ 2023-10-16 7:56 UTC (permalink / raw)
To: openembedded-core, badganchipv; +Cc: ranjitsinh.rathod
Notice that it references different CVE id:
https://nvd.nist.gov/vuln/detail/CVE-2023-5129
which was marked as a rejected duplicate of:
https://nvd.nist.gov/vuln/detail/CVE-2023-4863
but it's the same issue. Hence update CVE ID CVE-2023-4863
to CVE-2023-5129.patch.
Signed-off-by: Pawan <badganchipv@gmail.com>
---
meta/recipes-multimedia/webp/files/CVE-2023-5129.patch | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/meta/recipes-multimedia/webp/files/CVE-2023-5129.patch b/meta/recipes-multimedia/webp/files/CVE-2023-5129.patch
index eb77e193c2..ffff068c56 100644
--- a/meta/recipes-multimedia/webp/files/CVE-2023-5129.patch
+++ b/meta/recipes-multimedia/webp/files/CVE-2023-5129.patch
@@ -12,9 +12,16 @@ codes) streams are still decodable.
Bug: chromium:1479274
Change-Id: I31c36dbf3aa78d35ecf38706b50464fd3d375741
-CVE: CVE-2023-5129
+Notice that it references different CVE id:
+https://nvd.nist.gov/vuln/detail/CVE-2023-5129
+which was marked as a rejected duplicate of:
+https://nvd.nist.gov/vuln/detail/CVE-2023-4863
+but it's the same issue. Hence update CVE ID CVE-2023-4863
+
+CVE: CVE-2023-5129 CVE-2023-4863
Upstream-Status: Backport [https://github.com/webmproject/libwebp/commit/2af26267cdfcb63a88e5c74a85927a12d6ca1d76]
Signed-off-by: Colin McAllister <colinmca242@gmail.com>
+Signed-off-by: Pawan Badganchi <Pawan.Badganchi@kpit.com>
---
src/dec/vp8l_dec.c | 46 ++++++++++---------
src/dec/vp8li_dec.h | 2 +-
--
2.25.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [dunfell][PATCH] libwebp: Update CVE ID CVE-2023-4863
2023-10-16 7:56 [OE-core][dunfell][PATCH] libwebp: Update CVE ID CVE-2023-4863 Pawan
@ 2023-10-16 8:09 ` Pawan Badganchi
0 siblings, 0 replies; 2+ messages in thread
From: Pawan Badganchi @ 2023-10-16 8:09 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 20 bytes --]
Please ignore this
[-- Attachment #2: Type: text/html, Size: 20 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-10-16 8:09 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-10-16 7:56 [OE-core][dunfell][PATCH] libwebp: Update CVE ID CVE-2023-4863 Pawan
2023-10-16 8:09 ` [dunfell][PATCH] " Pawan Badganchi
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox