CVE-2014-9620 Limit the number of ELF notes processed - DoS Reference: https://security-tracker.debian.org/tracker/CVE-2014-9620 Report: http://mx.gw.com/pipermail/file/2014/001653.html Fix: https://github.com/file/file/commit/ce90e05774dd77d86cfc8dfa6da57b32816841c4 Introduced by: https://github.com/file/file/commit/956a45ab1c54b11304b367056f41905e72a02380#diff-bc5c24ef9f39a5f4963ca28ecbc645b3L423 ================================== CVE-2014-9621 Limit string printing to 100 chars - DoS References: https://security-tracker.debian.org/tracker/CVE-2014-9621 Report: http://mx.gw.com/pipermail/file/2014/001654.html Fix: https://github.com/file/file/commit/65437cee25199dbd385fb35901bc0011e164276c Introduced by: https://github.com/file/file/commit/c8451af8ab0c2e2a93ce93b9c68257d31576cc85 (5.16) (Introduced in 5.16) These CVEs affect dasiy, dizzy and master branches !!
Please ensure you have backported patches to all stable (daisy, dizzy and master).
I can confirm that master branch has already fixed it since it uses 5.22, for dizzy (5.18) and daisy (5.16), none of them can apply the two patches, I need do more work for them.
dizzy: http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=dizzy&id=86da1430b7ce05dfbdba2e57954394fdc38600a0 daisy: http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=daisy&id=46e8377c42030eb04972940cd022a8d214d477c7