All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH 1/3] package/exiv2: annotate CVE-2019-13504
@ 2020-02-29 21:32 Fabrice Fontaine
  2020-02-29 21:32 ` [Buildroot] [PATCH 2/3] package/exiv2: fix CVE-2019-17402 Fabrice Fontaine
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Fabrice Fontaine @ 2020-02-29 21:32 UTC (permalink / raw)
  To: buildroot

CVE-2019-13504 is misclassified (by our CVE tracker) as affecting
version 0.27.2, while in fact both commits that fixed this issue are
already in this version.

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
---
 package/exiv2/exiv2.mk | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/package/exiv2/exiv2.mk b/package/exiv2/exiv2.mk
index 228b3a980e..09988f49b2 100644
--- a/package/exiv2/exiv2.mk
+++ b/package/exiv2/exiv2.mk
@@ -10,6 +10,11 @@ EXIV2_INSTALL_STAGING = YES
 EXIV2_LICENSE = GPL-2.0+, BSD-3-Clause
 EXIV2_LICENSE_FILES = COPYING COPYING-CMAKE-SCRIPTS
 
+# CVE-2019-13504 is misclassified (by our CVE tracker) as affecting version
+# 0.27.2, while in fact both commits that fixed this issue are already in this
+# version.
+EXIV2_IGNORE_CVES += CVE-2019-13504
+
 EXIV2_CONF_OPTS += -DEXIV2_ENABLE_BUILD_SAMPLES=OFF
 
 # The following CMake variable disables a TRY_RUN call in the -pthread
-- 
2.25.0

^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2020-03-14 17:58 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-02-29 21:32 [Buildroot] [PATCH 1/3] package/exiv2: annotate CVE-2019-13504 Fabrice Fontaine
2020-02-29 21:32 ` [Buildroot] [PATCH 2/3] package/exiv2: fix CVE-2019-17402 Fabrice Fontaine
2020-03-14 17:58   ` Peter Korsgaard
2020-02-29 21:32 ` [Buildroot] [PATCH 3/3] package/exiv2: fix CVE-2019-20421 Fabrice Fontaine
2020-03-14 17:58   ` Peter Korsgaard
2020-02-29 22:21 ` [Buildroot] [PATCH 1/3] package/exiv2: annotate CVE-2019-13504 Yann E. MORIN
2020-02-29 22:28   ` Fabrice Fontaine
2020-03-01  7:29     ` Yann E. MORIN

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.