Go to file
Peter Korsgaard bc73055757 wavpack: add upstream security fixes
Fixes the following security issues:

CVE-2018-10536: An issue was discovered in WavPack 5.1.0 and earlier.  The
WAV parser component contains a vulnerability that allows writing to memory
because ParseRiffHeaderConfig in riff.c does not reject multiple format
chunks.

CVE-2018-10537: An issue was discovered in WavPack 5.1.0 and earlier.  The
W64 parser component contains a vulnerability that allows writing to memory
because ParseWave64HeaderConfig in wave64.c does not reject multiple format
chunks.

CVE-2018-10538: An issue was discovered in WavPack 5.1.0 and earlier for WAV
input.  Out-of-bounds writes can occur because ParseRiffHeaderConfig in
riff.c does not validate the sizes of unknown chunks before attempting
memory allocation, related to a lack of integer-overflow protection within a
bytes_to_copy calculation and subsequent malloc call, leading to
insufficient memory allocation.

CVE-2018-10539: An issue was discovered in WavPack 5.1.0 and earlier for
DSDiff input.  Out-of-bounds writes can occur because
ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown
chunks before attempting memory allocation, related to a lack of
integer-overflow protection within a bytes_to_copy calculation and
subsequent malloc call, leading to insufficient memory allocation.

CVE-2018-10540: An issue was discovered in WavPack 5.1.0 and earlier for W64
input.  Out-of-bounds writes can occur because ParseWave64HeaderConfig in
wave64.c does not validate the sizes of unknown chunks before attempting
memory allocation, related to a lack of integer-overflow protection within a
bytes_to_copy calculation and subsequent malloc call, leading to
insufficient memory allocation.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2018-05-21 17:47:08 +02:00
arch Revert "arch/arm: add cortex-m7 core" 2018-05-20 19:13:29 +02:00
board imx8mqevk: readme: Write the SoC name in capital letters 2018-05-17 22:21:23 +02:00
boot boot/uboot: default to kconfig buildsystem for latest version 2018-04-25 21:35:35 +02:00
configs configs/mx53loco: Adjust comment to reflect the real kernel version 2018-05-17 22:20:51 +02:00
docs docs/manual: using a branch name as FOO_VERSION does not work 2018-05-11 23:03:21 +02:00
fs fs/squashfs: add zstd support 2018-04-25 23:39:04 +02:00
linux linux: bump default to version 4.16.10 2018-05-21 17:46:43 +02:00
package wavpack: add upstream security fixes 2018-05-21 17:47:08 +02:00
support support/download/file: remove set -x 2018-05-13 22:26:43 +02:00
system skeleton: add /dev/fd, /dev/std{in, out, err} symlinks for static /dev on readonly rootfs 2018-05-01 21:53:45 +02:00
toolchain toolchain/buildroot: fix default of C library choice 2018-05-13 22:09:34 +02:00
utils scanpypi: add support for the new PyPI infrastructure 2018-04-18 17:11:47 +02:00
.defconfig
.flake8
.gitignore
.gitlab-ci.yml .gitlab-ci.yml: update after removal of freescale defconfigs 2018-05-06 17:36:37 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: extend check-package test to Config.* files 2018-04-01 10:16:35 +02:00
CHANGES CHANGES: additional updates for 2018.05-rc1 2018-05-09 22:53:39 +02:00
Config.in Config.in: add BR2_HOST_GCC_AT_LEAST_8 2018-05-02 14:50:14 +02:00
Config.in.legacy package/transmission: remove BR2_PACKAGE_TRANSMISSION_REMOTE 2018-05-20 15:38:46 +02:00
COPYING
DEVELOPERS DEVELOPERS: add myself for libnss 2018-05-19 23:13:23 +02:00
Makefile Update for 2018.05-rc1 2018-05-09 23:00:18 +02:00
Makefile.legacy
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches