* fetch by git to avoid github checksum surprises * 0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch was applied upstream
Signed-off-by: Andreas Müller <schnitzelt...@gmail.com> --- ...fo_header-reject-bmp-files-with-biBitCoun.patch | 31 ---------------------- .../{openjpeg_2.2.0.bb => openjpeg_2.3.0.bb} | 8 +++--- 2 files changed, 3 insertions(+), 36 deletions(-) delete mode 100644 meta-oe/recipes-graphics/openjpeg/files/0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch rename meta-oe/recipes-graphics/openjpeg/{openjpeg_2.2.0.bb => openjpeg_2.3.0.bb} (54%) diff --git a/meta-oe/recipes-graphics/openjpeg/files/0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch b/meta-oe/recipes-graphics/openjpeg/files/0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch deleted file mode 100644 index 866d9aa41..000000000 --- a/meta-oe/recipes-graphics/openjpeg/files/0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 226f07e4b49c2757b181c62e6841000c512054e3 Mon Sep 17 00:00:00 2001 -From: Even Rouault <even.roua...@spatialys.com> -Date: Mon, 14 Aug 2017 17:26:58 +0200 -Subject: [PATCH] bmp_read_info_header(): reject bmp files with biBitCount == 0 - (#983) - -Upstream-Status: Backport [https://github.com/uclouvain/openjpeg/commit/baf0c1ad4572daa89caa3b12985bdd93530f0dd7] -CVE: CVE-2017-12982 -Signed-off-by: Dengke Du <dengke...@windriver.com> ---- - src/bin/jp2/convertbmp.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/src/bin/jp2/convertbmp.c b/src/bin/jp2/convertbmp.c -index b49e7a0..2715fdf 100644 ---- a/src/bin/jp2/convertbmp.c -+++ b/src/bin/jp2/convertbmp.c -@@ -392,6 +392,10 @@ static OPJ_BOOL bmp_read_info_header(FILE* IN, OPJ_BITMAPINFOHEADER* header) - - header->biBitCount = (OPJ_UINT16)getc(IN); - header->biBitCount |= (OPJ_UINT16)((OPJ_UINT32)getc(IN) << 8); -+ if (header->biBitCount == 0) { -+ fprintf(stderr, "Error, invalid biBitCount %d\n", 0); -+ return OPJ_FALSE; -+ } - - if (header->biSize >= 40U) { - header->biCompression = (OPJ_UINT32)getc(IN); --- -2.8.1 - diff --git a/meta-oe/recipes-graphics/openjpeg/openjpeg_2.2.0.bb b/meta-oe/recipes-graphics/openjpeg/openjpeg_2.3.0.bb similarity index 54% rename from meta-oe/recipes-graphics/openjpeg/openjpeg_2.2.0.bb rename to meta-oe/recipes-graphics/openjpeg/openjpeg_2.3.0.bb index 22b75d962..d5d06206d 100644 --- a/meta-oe/recipes-graphics/openjpeg/openjpeg_2.2.0.bb +++ b/meta-oe/recipes-graphics/openjpeg/openjpeg_2.3.0.bb @@ -5,11 +5,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=c648878b4840d7babaade1303e7f108c" DEPENDS = "libpng tiff lcms zlib" -SRC_URI = "https://github.com/uclouvain/${BPN}/archive/v${PV}.tar.gz;downloadfilename=${BP}.tar.gz \ - file://0001-bmp_read_info_header-reject-bmp-files-with-biBitCoun.patch \ - " -SRC_URI[md5sum] = "269bb0b175476f3addcc0d03bd9a97b6" -SRC_URI[sha256sum] = "6fddbce5a618e910e03ad00d66e7fcd09cc6ee307ce69932666d54c73b7c6e7b" +SRC_URI = "git://github.com/uclouvain/openjpeg.git" +SRCREV = "081de4b15f54cb4482035b7bf5e3fb443e4bc84b" +S = "${WORKDIR}/git" inherit cmake -- 2.14.4 -- _______________________________________________ Openembedded-devel mailing list Openembedded-devel@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-devel