Re: [OE-core] [daisy][PATCH] file: CVE-2014-9620 and CVE-2014-9621

2015-02-02 Thread Chong Lu
On 02/02/2015 09:55 PM, Saul Wold wrote: I had some issues with this patch on the Autobuilder, it failed in some cases for nativesdk-file on some, but not all machines of the autobuilder. See:

Re: [OE-core] [daisy][PATCH] file: CVE-2014-9620 and CVE-2014-9621

2015-02-02 Thread Saul Wold
I had some issues with this patch on the Autobuilder, it failed in some cases for nativesdk-file on some, but not all machines of the autobuilder. See: https://autobuilder.yoctoproject.org/main/builders/nightly-arm/builds/178/steps/Building%20Toolchain%20Images/logs/stdio That's one

Re: [OE-core] [daisy][PATCH] file: CVE-2014-9620 and CVE-2014-9621

2015-01-29 Thread Chong Lu
ping //Chong On 01/22/2015 05:28 PM, Chong Lu wrote: CVE-2014-9620: Limit the number of ELF notes processed - DoS CVE-2014-9621: Limit string printing to 100 chars - DoS The patch comes from: https://github.com/file/file/commit/6ce24f35cd4a43c4bdd249e8e0c4952c1f8eac67

Re: [OE-core] [daisy][PATCH] file: CVE-2014-9620 and CVE-2014-9621

2015-01-29 Thread Saul Wold
On 01/29/2015 05:18 PM, Chong Lu wrote: ping Added to the sgw/daisy branch, will be tested on AB soon Sau! //Chong On 01/22/2015 05:28 PM, Chong Lu wrote: CVE-2014-9620: Limit the number of ELF notes processed - DoS CVE-2014-9621: Limit string printing to 100 chars - DoS The patch comes

[OE-core] [daisy][PATCH] file: CVE-2014-9620 and CVE-2014-9621

2015-01-22 Thread Chong Lu
CVE-2014-9620: Limit the number of ELF notes processed - DoS CVE-2014-9621: Limit string printing to 100 chars - DoS The patch comes from: https://github.com/file/file/commit/6ce24f35cd4a43c4bdd249e8e0c4952c1f8eac67 https://github.com/file/file/commit/0056ec32255de1de973574b0300161a1568767d6