package/qt5base: add upstream security patch for LTS variant
authorPeter Seiderer <ps.report@gmx.net>
Thu, 30 Jan 2020 21:13:34 +0000 (22:13 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 1 Feb 2020 22:45:33 +0000 (23:45 +0100)
commitc0607b38c862a6bd556d6f8c1a7d503bab9ede75
tree026c3a70d135a8eabf36ba64ee0e4527f7c62770
parentd8663e6ff1e88261b45f4477c4213c94b9ed54d6
package/qt5base: add upstream security patch for LTS variant

Fixed the following security issue:

- CVE-2020-0569: QPluginLoader in Qt versions 5.0.0 through 5.13.2 would
  search for certain plugins first on the current working directory of the
  application, which allows an attacker that can place files in the file
  system and influence the working directory of Qt-based applications to
  load and execute malicious code.  This issue was verified on macOS and
  Linux and probably affects all other Unix operating systems.  This issue
  does not affect Windows.

For details, see the advisory:
https://www.openwall.com/lists/oss-security/2020/01/30/1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Peter: extend commit message]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/qt5/qt5base/5.6.3/0005-Do-not-load-plugin-from-the-PWD.patch [new file with mode: 0644]