Files
buildroot/package
Raphaël Mélotte 0f4fef076f package/libfreeglut: add upstream security fix for CVE-2024-2425{8, 9}
Fixes the following security issues:

- CVE-2024-24258: freeglut 3.4.0 was discovered to contain a memory leak
via the menuEntry variable in the glutAddSubMenu function.
- CVE-2024-24259: freeglut through 3.4.0 was discovered to contain a
memory leak via the menuEntry variable in the glutAddMenuEntry
function.

https://nvd.nist.gov/vuln/detail/CVE-2024-24258
https://nvd.nist.gov/vuln/detail/CVE-2024-24259

The CVEs are not technically reported for the libfreeglut package
itself (which doesn't have a CPE identifier) but for mupdf.

Note that mudpf provides its own (old) version of freeglut, but our
mupdf package uses the Buildroot-provided freeglut (which now contains
the fix).

It also has to be noted that a more recent release of libfreeglut
exists upstream, and it fixes the same CVEs.  Bumping our package
version however requires more work that can be done separately.
Including this patch first also has the advantage that it can easily
be backported wherever it's needed.

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2025-04-02 21:14:34 +02:00
..
2025-03-31 21:38:25 +02:00
2025-03-28 19:39:45 +01:00
2025-03-25 19:35:17 +01:00
2025-03-30 22:21:22 +02:00
2025-03-30 11:09:55 +02:00
2025-03-29 21:24:21 +01:00
2025-03-22 12:34:21 +01:00
2025-03-24 20:52:58 +01:00
2025-03-15 22:22:10 +01:00
2025-03-18 21:53:24 +01:00
2025-03-19 00:07:17 +01:00
2025-03-25 19:23:48 +01:00
2025-03-10 21:15:14 +01:00
2025-03-15 22:09:10 +01:00
2025-03-05 22:51:06 +01:00
2025-03-28 19:39:45 +01:00
2025-03-25 23:02:14 +01:00
2025-04-01 21:33:44 +02:00
2025-03-24 21:00:42 +01:00
2025-03-31 21:48:05 +02:00
2025-03-11 21:14:43 +01:00
2025-03-18 21:55:39 +01:00
2025-04-01 21:33:44 +02:00