Go to file
Fabrice Fontaine dd1e3f6065 package/libxslt: security bump to version 1.1.34
Fixes the following security issues:

- CVE-2019-13117: In numbers.c in libxslt 1.1.33, an xsl:number with certain
  format strings could lead to a uninitialized read in
  xsltNumberFormatInsertNumbers.  This could allow an attacker to discern
  whether a byte on the stack contains the characters A, a, I, i, or 0, or
  any other character.

- CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping
  characters of an xsl:number instruction was too narrow and an invalid
  character/length combination could be passed to xsltNumberFormatDecimal,
  leading to a read of uninitialized stack data.

- CVE-2019-18197: In xsltCopyText in transform.c in libxslt 1.1.33, a
  pointer variable isn't reset under certain circumstances.  If the relevant
  memory area happened to be freed and reused in a certain way, a bounds
  check could fail and memory outside a buffer could be written to, or
  uninitialized data could be disclosed.

Remove patch (already in version)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Peter: mention security impact]
(cherry picked from commit 5645107c39)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2020-02-04 11:22:48 +01:00
arch arch/riscv: set the default float ABI based on ISA extensions 2019-09-19 21:43:53 +02:00
board board/freescale/common/imx: use nodtb variant in uboot images for 8M 2019-12-25 22:54:48 +01:00
boot boot/optee-os: bump version to 3.7.0 2019-10-29 22:25:18 +01:00
configs configs/licheepi_zero: U-Boot needs pylibfdt 2019-12-23 19:01:16 +01:00
docs docs/manual: fix typo 2020-01-10 15:08:02 +01:00
fs fs: don't use := when not needed 2019-10-27 10:35:06 +01:00
linux {linux, linux-headers}: bump 4.{14, 19}.x / 5.4.x series 2020-01-11 11:47:11 +01:00
package package/libxslt: security bump to version 1.1.34 2020-02-04 11:22:48 +01:00
support Update for 2019.11 2019-12-01 22:39:47 +01:00
system system: allow not setting a default, system-wide time zone 2019-11-27 21:48:38 +01:00
toolchain package/musl: add an upstream URL to Config.in 2019-11-29 09:44:09 +01:00
utils utils/scanpypi: remind developer about updating DEVELOPERS and Config.in 2020-01-07 22:26:04 +01:00
.defconfig
.flake8
.gitignore
.gitlab-ci.yml gitlab-ci: use our updated docker base image 2019-10-27 21:52:28 +01:00
.gitlab-ci.yml.in gitlab-ci: use our updated docker base image 2019-10-27 21:52:28 +01:00
CHANGES Update for 2019.11.1 2020-01-12 13:18:07 +01:00
Config.in Config.in: disable PIC/PIE if the toolchain does not support PIE 2019-10-28 08:43:22 +01:00
Config.in.legacy Config.in.legacy: fix small typo 2019-11-10 21:51:16 +01:00
COPYING
DEVELOPERS DEVELOPERS: add me as a maintainer for the NETCONF stack 2019-12-22 21:28:19 +01:00
Makefile Update for 2019.11.1 2020-01-12 13:18:07 +01:00
Makefile.legacy
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches