]> git.proxmox.com Git - mirror_edk2.git/commit
MdePkg: Add more checker in UefiDecompressLib to access the valid buffer only (CVE...
authorLiming Gao <liming.gao@intel.com>
Tue, 16 Oct 2018 02:06:11 +0000 (10:06 +0800)
committerLiming Gao <liming.gao@intel.com>
Wed, 24 Oct 2018 00:24:14 +0000 (08:24 +0800)
commit2ec7953d49677142c5f7552e9e3d96fb406ba0c4
treed3448d08167e41b425410fb6a7874d980596fe86
parent68099b52b0fcc1d45864154954d776d91afb33e0
MdePkg: Add more checker in UefiDecompressLib to access the valid buffer only (CVE FIX)

Fix CVE-2017-5731,CVE-2017-5732,CVE-2017-5733,CVE-2017-5734,CVE-2017-5735
https://bugzilla.tianocore.org/show_bug.cgi?id=686

Contributed-under: TianoCore Contribution Agreement 1.1
Signed-off-by: Holtsclaw Brent <brent.holtsclaw@intel.com>
Signed-off-by: Liming Gao <liming.gao@intel.com>
Reviewed-by: Star Zeng <star.zeng@intel.com>
Acked-by: Laszlo Ersek <lersek@redhat.com>
MdePkg/Library/BaseUefiDecompressLib/BaseUefiDecompressLib.c