Re: [OE-core] [PATCH 3/3] libxfont: Security Advisory - libxfont - CVE-2015-1804

2015-04-26 Thread Zhou, Li
Update the patches for adding Upstream-Status in 2/3 and 3/3. On 04/24/2015 06:16 PM, Richard Purdie wrote: On Fri, 2015-04-24 at 10:19 +0800, Li Zhou wrote: bdfReadCharacters: ensure metrics fit into xCharInfo struct We use 32-bit ints to read from the bdf file, but then try to stick into a

Re: [OE-core] [PATCH 3/3] libxfont: Security Advisory - libxfont - CVE-2015-1804

2015-04-24 Thread Richard Purdie
On Fri, 2015-04-24 at 10:19 +0800, Li Zhou wrote: bdfReadCharacters: ensure metrics fit into xCharInfo struct We use 32-bit ints to read from the bdf file, but then try to stick into a 16-bit int in the xCharInfo struct, so make sure they won't overflow that range. Signed-off-by: Li Zhou

[OE-core] [PATCH 3/3] libxfont: Security Advisory - libxfont - CVE-2015-1804

2015-04-23 Thread Li Zhou
bdfReadCharacters: ensure metrics fit into xCharInfo struct We use 32-bit ints to read from the bdf file, but then try to stick into a 16-bit int in the xCharInfo struct, so make sure they won't overflow that range. Signed-off-by: Li Zhou li.z...@windriver.com ---