I have made some patches for libfpx that fixes CVE-2017-12921 and CVE-2017-12925 and possibly CVE-2017-12920.
The patches are available at http://cvsweb.netbsd.org/bsdweb.cgi/pkg ... h_tag=MAIN
I have tested the patches against Agustinos payloads for these CVEs and they don't crash.
Regards,
Niclas Rosenvik
libfpx cve fixes
Re: libfpx cve fixes
Niclas, thanks for the patches. We applied them against libfpx and have a libfpx-1.3.9-10 release scheduled by sometime tomorrow.