mirror of
https://github.com/openwrt/openwrt.git
synced 2024-12-27 01:11:14 +00:00
5f189f2f33
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow
in inflate in inflate.c via a large gzip header extra field. NOTE: only
applications that call inflateGetHeader are affected. Some common
applications bundle the affected zlib source code but may be unable to
call inflateGetHeader.
Fixes: CVE-2022-37434
References: https://github.com/ivd38/zlib_overflow
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit
|
||
---|---|---|
.. | ||
001-neon-implementation-of-adler32.patch | ||
002-arm-specific-optimisations-for-inflate.patch | ||
003-arm-specific-optimisations-for-inflate.patch | ||
004-attach-sourcefiles-in-patch-002-to-buildsystem.patch | ||
005-relative-pkg-config-paths.patch | ||
006-fix-compressor-crash-on-certain-inputs.patch | ||
006-fix-CVE-2022-37434.patch |