All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH 00/10] Misc CVE ignores
@ 2021-04-21 20:42 Matt Weber
  2021-04-21 20:42 ` [Buildroot] [PATCH 01/10] package/bind: ignore CVE-2017-3139 Matt Weber
                   ` (10 more replies)
  0 siblings, 11 replies; 16+ messages in thread
From: Matt Weber @ 2021-04-21 20:42 UTC (permalink / raw)
  To: buildroot

 * I'm working on upstream NVD fixes for some of these.

 * There are roughly half of the ignore cases that are a bit of a
   challenge to identify where the fix was clearly tracked into
   a specific version. I tried to document in each commit as much
   as a could by linking to conversations clarifying the details.

Matt Weber (10):
  package/bind: ignore CVE-2017-3139
  package/coreutils: ignore CVE-2013-0221, CVE-2013-0222, CVE-2013-0223
  package/bind: ignore CVE-2019-6470
  package/cmake: ignore CVE-2016-10642
  package/flex: ignore CVE-2019-6293
  package/hostapd: ignore CVE-2021-30004 when using openssl
  package/wpa_supplicant: ignore CVE-2021-30004 when using openssl
  package/ncurses: ignore CVE-2018-10754, CVE-2018-19211,
    CVE-2018-19217, CVE-2019-17594, CVE-2019-17595
  package/rsyslog: ignore CVE-2015-3243
  package/tar: ignore CVE-2007-4476

 package/bind/bind.mk                     | 4 ++++
 package/cmake/cmake.mk                   | 2 ++
 package/coreutils/coreutils.mk           | 4 ++++
 package/flex/flex.mk                     | 3 +++
 package/hostapd/hostapd.mk               | 2 ++
 package/ncurses/ncurses.mk               | 6 ++++++
 package/rsyslog/rsyslog.mk               | 4 ++++
 package/tar/tar.mk                       | 2 ++
 package/wpa_supplicant/wpa_supplicant.mk | 2 ++
 9 files changed, 29 insertions(+)

-- 
2.17.1

^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2021-04-26 20:29 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-04-21 20:42 [Buildroot] [PATCH 00/10] Misc CVE ignores Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 01/10] package/bind: ignore CVE-2017-3139 Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 02/10] package/coreutils: ignore CVE-2013-0221, CVE-2013-0222, CVE-2013-0223 Matt Weber
2021-04-26 19:15   ` Peter Korsgaard
2021-04-21 20:42 ` [Buildroot] [PATCH 03/10] package/bind: ignore CVE-2019-6470 Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 04/10] package/cmake: ignore CVE-2016-10642 Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 05/10] package/flex: ignore CVE-2019-6293 Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 06/10] package/hostapd: ignore CVE-2021-30004 when using openssl Matt Weber
2021-04-26 19:52   ` Peter Korsgaard
2021-04-21 20:42 ` [Buildroot] [PATCH 07/10] package/wpa_supplicant: " Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 08/10] package/ncurses: ignore CVE-2018-10754, CVE-2018-19211, CVE-2018-19217, CVE-2019-17594, CVE-2019-17595 Matt Weber
2021-04-21 20:42 ` [Buildroot] [PATCH 09/10] package/rsyslog: ignore CVE-2015-3243 Matt Weber
2021-04-26 20:26   ` Peter Korsgaard
2021-04-21 20:42 ` [Buildroot] [PATCH 10/10] package/tar: ignore CVE-2007-4476 Matt Weber
2021-04-24  9:29 ` [Buildroot] [PATCH 00/10] Misc CVE ignores Yann E. MORIN
2021-04-26 20:29   ` Peter Korsgaard

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.