bsdiff: Add patches for CVEs
authorHauke Mehrtens <hauke@hauke-m.de>
Sat, 7 Oct 2023 19:07:20 +0000 (21:07 +0200)
committerHauke Mehrtens <hauke@hauke-m.de>
Mon, 9 Oct 2023 21:45:35 +0000 (23:45 +0200)
commit6637af95aa9085c8367ce8184b0fe6917365c3d3
tree047e2fcf549f70e2cdd777e540d2308a8bfa3e8c
parentfadbec8857efddf5d1b55b77af56afac8428a943
bsdiff: Add patches for CVEs

Add two patches from Debian fixing CVEs in the bsdiff application.
CVE-2014-9862: Heap vulnerability in bspatch
CVE-2020-14315: Memory Corruption Vulnerability in bspatch

Copied the patches from this location:
https://salsa.debian.org/debian/bsdiff/-/blob/debian/latest/debian/patches/20-CVE-2014-9862.patch
https://salsa.debian.org/debian/bsdiff/-/blob/debian/latest/debian/patches/33-CVE-2020-14315.patch

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
(cherry picked from commit cac723e8b8748938b8d80603578c60189fc32b24)
package/utils/bsdiff/Makefile
package/utils/bsdiff/patches/001-musl.patch
package/utils/bsdiff/patches/020-CVE-2014-9862.patch [new file with mode: 0644]
package/utils/bsdiff/patches/033-CVE-2020-14315.patch [new file with mode: 0644]