bsdiff: Add patches for CVEs
authorHauke Mehrtens <hauke@hauke-m.de>
Sat, 7 Oct 2023 19:07:20 +0000 (21:07 +0200)
committerHauke Mehrtens <hauke@hauke-m.de>
Sun, 19 Nov 2023 13:58:44 +0000 (14:58 +0100)
commit3af93be5a15cf392bb4e8ef20663331168e982cd
tree2d5b587e4ed821d6c701d7e93f6c85030a66194e
parentb87913e21d9e9ddaeb8dc149e0335a4a7ade0015
bsdiff: Add patches for CVEs

Add two patches from Debian fixing CVEs in the bsdiff application.
CVE-2014-9862: Heap vulnerability in bspatch
CVE-2020-14315: Memory Corruption Vulnerability in bspatch

Copied the patches from this location:
https://salsa.debian.org/debian/bsdiff/-/blob/debian/latest/debian/patches/20-CVE-2014-9862.patch
https://salsa.debian.org/debian/bsdiff/-/blob/debian/latest/debian/patches/33-CVE-2020-14315.patch

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
(cherry picked from commit cac723e8b8748938b8d80603578c60189fc32b24)
package/utils/bsdiff/Makefile
package/utils/bsdiff/patches/001-musl.patch
package/utils/bsdiff/patches/020-CVE-2014-9862.patch [new file with mode: 0644]
package/utils/bsdiff/patches/033-CVE-2020-14315.patch [new file with mode: 0644]