Browse Source

grep: Fix CVE-2015-1345 heap buffer overrun

Julen Landa Alustiza 10 years ago
parent
commit
e0edca76da

+ 1
- 1
utils/grep/Makefile View File

@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
9 9
 
10 10
 PKG_NAME:=grep
11 11
 PKG_VERSION:=2.21
12
-PKG_RELEASE:=1
12
+PKG_RELEASE:=2
13 13
 
14 14
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.xz
15 15
 PKG_SOURCE_URL:=@GNU/grep

+ 15
- 0
utils/grep/patches/0001-grep-F-fix-a-heap-buffer-read-overrun.patch View File

@@ -0,0 +1,15 @@
1
+diff --git a/src/kwset.c b/src/kwset.c
2
+index 4003c8d..376f7c3 100644
3
+--- a/src/kwset.c
4
++++ b/src/kwset.c
5
+@@ -643,6 +643,8 @@ bmexec_trans (kwset_t kwset, char const *text, size_t size)
6
+                     if (! tp)
7
+                       return -1;
8
+                     tp++;
9
++                    if (ep <= tp)
10
++                      break;
11
+                   }
12
+               }
13
+           }
14
+--
15
+cgit v0.9.0.2