openwrt/package/libs/zlib/patches
Petr Štetiar 5f189f2f33 zlib: backport fix for heap-based buffer over-read (CVE-2022-37434)
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow
in inflate in inflate.c via a large gzip header extra field. NOTE: only
applications that call inflateGetHeader are affected. Some common
applications bundle the affected zlib source code but may be unable to
call inflateGetHeader.

Fixes: CVE-2022-37434
References: https://github.com/ivd38/zlib_overflow
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit 7df6795d4c)
2022-08-08 10:00:39 +02:00
..
001-neon-implementation-of-adler32.patch package/libs/zlib: Add ARM and NEON optimizations 2018-01-02 17:11:12 +01:00
002-arm-specific-optimisations-for-inflate.patch zlib: properly split patches 2021-02-25 14:41:40 +01:00
003-arm-specific-optimisations-for-inflate.patch zlib: properly split patches 2021-02-25 14:41:40 +01:00
004-attach-sourcefiles-in-patch-002-to-buildsystem.patch zlib: properly split patches 2021-02-25 14:41:40 +01:00
005-relative-pkg-config-paths.patch zlib: properly split patches 2021-02-25 14:41:40 +01:00
006-fix-compressor-crash-on-certain-inputs.patch zlib: backport security fix for a reproducible crash in compressor 2022-03-24 09:40:12 +01:00
006-fix-CVE-2022-37434.patch zlib: backport fix for heap-based buffer over-read (CVE-2022-37434) 2022-08-08 10:00:39 +02:00