summaryrefslogtreecommitdiffstats
path: root/package/mcrypt/mcrypt-CVE-2012-4409.patch
diff options
context:
space:
mode:
authorGustavo Zacarias <gustavo@zacarias.com.ar>2013-01-07 08:13:00 +0000
committerPeter Korsgaard <jacmet@sunsite.dk>2013-01-13 21:30:23 +0100
commit9e02c32fd6a064bf256c5e76abbf65e432892489 (patch)
treec27e257573b54dcdeaaeebce19aaa380843b147c /package/mcrypt/mcrypt-CVE-2012-4409.patch
parenteddffaad60357d738550bb832acb419c1452e633 (diff)
downloadbuildroot-novena-9e02c32fd6a064bf256c5e76abbf65e432892489.tar.gz
buildroot-novena-9e02c32fd6a064bf256c5e76abbf65e432892489.zip
mcrypt: new package
Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar> Signed-off-by: Peter Korsgaard <jacmet@sunsite.dk>
Diffstat (limited to 'package/mcrypt/mcrypt-CVE-2012-4409.patch')
-rw-r--r--package/mcrypt/mcrypt-CVE-2012-4409.patch25
1 files changed, 25 insertions, 0 deletions
diff --git a/package/mcrypt/mcrypt-CVE-2012-4409.patch b/package/mcrypt/mcrypt-CVE-2012-4409.patch
new file mode 100644
index 000000000..97c658bb2
--- /dev/null
+++ b/package/mcrypt/mcrypt-CVE-2012-4409.patch
@@ -0,0 +1,25 @@
+From 3efb40e17ce4f76717ae17a1ce1e1f747ddf59fd Mon Sep 17 00:00:00 2001
+From: Alon Bar-Lev <alon.barlev@gmail.com>
+Date: Sat, 22 Dec 2012 22:37:06 +0200
+Subject: [PATCH] cleanup: buffer overflow
+
+---
+ src/extra.c | 2 ++
+ 1 files changed, 2 insertions(+), 0 deletions(-)
+
+diff --git a/src/extra.c b/src/extra.c
+index 3082f82..c7a1ac0 100644
+--- a/src/extra.c
++++ b/src/extra.c
+@@ -241,6 +241,8 @@ int check_file_head(FILE * fstream, char *algorithm, char *mode,
+ if (m_getbit(6, flags) == 1) { /* if the salt bit is set */
+ if (m_getbit(0, sflag) != 0) { /* if the first bit is set */
+ *salt_size = m_setbit(0, sflag, 0);
++ if (*salt_size > sizeof(tmp_buf))
++ err_quit(_("Salt is too long\n"));
+ if (*salt_size > 0) {
+ fread(tmp_buf, 1, *salt_size,
+ fstream);
+--
+1.7.8.6
+