p7zip fixes for CVE-2018-5996 and CVE-2016-9296


Peter Marko
 

Dear maintainers,

 

CVE-2018-5996 and CVE-2016-9296 were fixed in dunfell but these patched did not make it to master (and thus also not to langdale and kirkstone).

Could you please pick them to these three branches?

https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-extended/p7zip?h=dunfell&id=4f701b46551d7a68aaed2c59943007f1e685c800

https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-extended/p7zip?h=dunfell&id=9d722e88d79e3a19d2ae07ac922109c18e2f5559

 

I can also send new patches if it is needed.

 

Thanks,

  Peter


Peter Marko
 

gentle ping

 

From: openembedded-devel@... <openembedded-devel@...> On Behalf Of Peter Marko via lists.openembedded.org
Sent: Tuesday, March 21, 2023 18:18
To: openembedded-devel@...
Subject: [oe] p7zip fixes for CVE-2018-5996 and CVE-2016-9296

 

> Dear maintainers,

> CVE-2018-5996 and CVE-2016-9296 were fixed in dunfell but these patched did not make it to master (and thus also not to langdale and kirkstone).

> Could you please pick them to these three branches?

> https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-extended/p7zip?h=dunfell&id=4f701b46551d7a68aaed2c59943007f1e685c800

> https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-extended/p7zip?h=dunfell&id=9d722e88d79e3a19d2ae07ac922109c18e2f5559

> I can also send new patches if it is needed.

> Thanks,

>  Peter