Go to file
Peter Korsgaard 505a70edbe package/gd: add post-2.2.5 security fixes from upstream
Fixes the following security vulnerablities:

- CVE-2018-1000222: Libgd version 2.2.5 contains a Double Free Vulnerability
  vulnerability in gdImageBmpPtr Function that can result in Remote Code
  Execution .  This attack appear to be exploitable via Specially Crafted
  Jpeg Image can trigger double free

- CVE-2018-5711: gd_gif_in.c in the GD Graphics Library (aka libgd), as used
  in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x
  before 7.2.1, has an integer signedness error that leads to an infinite
  loop via a crafted GIF file, as demonstrated by a call to the
  imagecreatefromgif or imagecreatefromstring PHP function

- CVE-2019-11038: When using the gdImageCreateFromXbm() function in the GD
  Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP
  versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it
  is possible to supply data that will cause the function to use the value
  of uninitialized variable.  This may lead to disclosing contents of the
  stack that has been left there by previous code

- CVE-2019-6978: The GD Graphics Library (aka LibGD) 2.2.5 has a double free
  in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2019-10-21 21:45:31 +02:00
arch arch/riscv: set the default float ABI based on ISA extensions 2019-09-19 21:43:53 +02:00
board board: Add FriendlyARM Nanopi NEO Plus2 support 2019-10-19 22:46:04 +02:00
boot boot/opensbi: bump to 0.5 2019-10-17 09:49:56 +02:00
configs configs/imx6-sabresd_qt5: Remove the swrast option 2019-10-20 00:22:28 +02:00
docs docs/manual: fix Config.in option that cargo packages must depend on 2019-10-10 23:28:17 +02:00
fs fs/common.mk: enable multithreaded xz compression 2019-08-03 19:29:47 +02:00
linux {linux, linux-headers}: bump 4.{4, 9, 14, 19}.x / 5.3.x series 2019-10-18 09:30:59 +02:00
package package/gd: add post-2.2.5 security fixes from upstream 2019-10-21 21:45:31 +02:00
support support/testing: test_syslog_ng: improve commands 2019-10-16 21:33:04 +02:00
system package/netifrc: add support for BR2_SYSTEM_DHCP 2019-09-23 22:57:04 +02:00
toolchain {linux, linux-headers}: bump to version 5.3.1 2019-09-28 22:44:50 +02:00
utils scanpypi: write every license file once 2019-10-11 23:04:40 +02:00
.defconfig
.flake8 .flake8: fix check for 80/132 columns 2019-04-10 12:31:33 +02:00
.gitignore
.gitlab-ci.yml board: Add FriendlyARM Nanopi NEO Plus2 support 2019-10-19 22:46:04 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: add trigger per job 2019-05-01 15:42:45 +02:00
CHANGES Update for 2019.02.6 2019-10-04 09:27:30 +02:00
Config.in core: split generated kconfig file 2019-08-04 00:13:37 +02:00
Config.in.legacy package/linux-headers: drop support for 5.2.x headers 2019-10-18 09:30:38 +02:00
COPYING
DEVELOPERS DEVELOPERS: remove myself from asterisk 2019-10-21 21:34:59 +02:00
Makefile Merge branch 'next' 2019-09-03 15:03:02 +02:00
Makefile.legacy
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches