From patchwork Thu Jan 4 12:40:10 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Florian Weimer X-Patchwork-Id: 855586 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=sourceware.org (client-ip=209.132.180.131; helo=sourceware.org; envelope-from=libc-alpha-return-88818-incoming=patchwork.ozlabs.org@sourceware.org; receiver=) Authentication-Results: ozlabs.org; dkim=pass (1024-bit key; secure) header.d=sourceware.org header.i=@sourceware.org header.b="jQuJeKOc"; dkim-atps=neutral Received: from sourceware.org (server1.sourceware.org [209.132.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3zC6pF2KWcz9s7s for ; Thu, 4 Jan 2018 23:40:20 +1100 (AEDT) DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:to:from:subject:message-id:date:mime-version :content-type; q=dns; s=default; b=KB6SL6dczIA7ANblIgYhcQ+gSIG20 TM1D7XL/U7SnmSxq42jGdVSJKbS3JsA0tdUDMP3naSMNjpduw5TppfBSZFocdCae kAYwOhQzHAjUYWQbVNa01Gm4TxAugKDy6z0Ltkl3Fc80j2a+5BVTUahmx98OOhQu CX/a8n+y/9c1UM= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:to:from:subject:message-id:date:mime-version :content-type; s=default; bh=e25Cu0nlcTM0dTnnGtk0qHBmuT4=; b=jQu JeKOckNJfxqvwBica0mhhgfWoKXj5XcTA9tmEOGgyTcdwvvB+J+qB0yqQK1Truoy VNQqRR8aoMHbEFGpT8bpXFCh9bOJjrTKBypyyVA8op1pZXGmR3LY6XH2n+KWET/V WJ0B9cc1C+BMYbTyQ+WN5Lpl8qH5gbtp0t3fKrkg= Received: (qmail 97447 invoked by alias); 4 Jan 2018 12:40:14 -0000 Mailing-List: contact libc-alpha-help@sourceware.org; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: libc-alpha-owner@sourceware.org Delivered-To: mailing list libc-alpha@sourceware.org Received: (qmail 97435 invoked by uid 89); 4 Jan 2018 12:40:14 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-26.9 required=5.0 tests=BAYES_00, GIT_PATCH_0, GIT_PATCH_1, GIT_PATCH_2, GIT_PATCH_3, SPF_HELO_PASS, T_RP_MATCHES_RCVD autolearn=ham version=3.3.2 spammy= X-HELO: mx1.redhat.com To: GNU C Library From: Florian Weimer Subject: [PATCH COMMITTED] Mention CVE-2017-16997 in ChangeLog Message-ID: Date: Thu, 4 Jan 2018 13:40:10 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0 MIME-Version: 1.0 commit 31f96325ca03429053199403651bb1b1b4db1dfb Author: Florian Weimer Date: Thu Jan 4 13:39:21 2018 +0100 Mention CVE-2017-16997 in ChangeLog diff --git a/ChangeLog b/ChangeLog index 40e4d1b4eb..878a738a32 100644 --- a/ChangeLog +++ b/ChangeLog @@ -109,6 +109,7 @@ Dmitry V. Levin [BZ #22625] + CVE-2017-16997 * elf/dl-load.c (fillin_rpath): Check for empty tokens before dynamic string token expansion. Check for NULL pointer or empty string possibly returned by expand_dynamic_string_token.