app-emulation/spice: fix vuln 0.13.1, bug #584126
authorMatthias Maier <tamiko@gentoo.org>
Tue, 14 Jun 2016 05:37:13 +0000 (00:37 -0500)
committerMatthias Maier <tamiko@gentoo.org>
Tue, 14 Jun 2016 05:46:47 +0000 (00:46 -0500)
commit76546db063fa388fbd42de1860e0d79d17948011
tree2d125ca3c1c34f9adab27d3614dbe663a3526397
parente78aee5d6b747e4dd0c6aed30b959107957a7c17
app-emulation/spice: fix vuln 0.13.1, bug #584126

Apply the following patches to 0.13.1:

CVE-2016-2150:

  Commits 69628ea1375282cb7ca5b4dc4410e7aa67e0fc02
  Commits 790d8f3e53d324f496fc719498422e433aae8654

  *instead of* 0067-create-a-function-to-validate-surface-parameters.patch
  *instead of* 0068-improve-primary-surface-parameter-checks.patch

CVE-2016-0749:

  Ported the following commits to 0.13.1 (patches did not apply due to
  refactoring of some internal data structures and renaming).

  *modified* 0065-smartcard-add-a-ref-to-item-before-adding-to-pipe.patch
  *modified* 0066-smartcard-allocate-msg-with-the-expected-size.patch

Gentoo-Bug: 584126

Package-Manager: portage-2.2.28
app-emulation/spice/files/0.13.1-CVE-2016-0749-p1.patch [new file with mode: 0644]
app-emulation/spice/files/0.13.1-CVE-2016-0749-p2.patch [new file with mode: 0644]
app-emulation/spice/files/0.13.1-CVE-2016-2150-p1.patch [new file with mode: 0644]
app-emulation/spice/files/0.13.1-CVE-2016-2150-p2.patch [new file with mode: 0644]
app-emulation/spice/spice-0.13.1-r2.ebuild [new file with mode: 0644]