+ Check header size indicator against expected size (CVE-2022-23645 bsc#1196240)

OBS-URL: https://build.opensuse.org/package/show/security/swtpm?expand=0&rev=31
This commit is contained in:
Marcus Meissner 2023-03-07 08:25:52 +00:00 committed by Git OBS Bridge
parent 5848fe1a37
commit 93f24082f9

View File

@ -21,7 +21,7 @@ Mon Mar 6 16:34:33 UTC 2023 - Alberto Planas Dominguez <aplanas@suse.com>
+ Use uint64_t in tlv_data_append() to avoid integer overflows
+ Use uint64_t to avoid integer wrap-around when adding a uint32_t
+ Do not chdir(/) when using --daemon
+ Check header size indicator against expected size (CVE-2022-23645)
+ Check header size indicator against expected size (CVE-2022-23645 bsc#1196240)
+ Fixes for gcc 12.2.1 -fanalyzer
* build-sys:
+ Fix configure script to support _FORTIFY_SOURCE=3