All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Steve Sakoman" <steve@sakoman.com>
To: openembedded-core@lists.openembedded.org
Subject: [OE-core][dunfell 13/22] logrotate: Exclude CVE-2011-1548,1549,1550 from cve-check
Date: Wed, 12 May 2021 04:56:52 -1000	[thread overview]
Message-ID: <7222f10e99e5a345c68feb254d309e55024ef4aa.1620831171.git.steve@sakoman.com> (raw)
In-Reply-To: <cover.1620831171.git.steve@sakoman.com>

From: Richard Purdie <richard.purdie@linuxfoundation.org>

These CVEs apply to the way logrotate was installed on Gentoo, Debian
and SUSE, exclude from cve-check as they don't apply to OE.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 23643016f3b8794db772e333ff0b8f598571b628)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
---
 meta/recipes-extended/logrotate/logrotate_3.15.1.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta/recipes-extended/logrotate/logrotate_3.15.1.bb b/meta/recipes-extended/logrotate/logrotate_3.15.1.bb
index 503a0622b1..7c1b77add8 100644
--- a/meta/recipes-extended/logrotate/logrotate_3.15.1.bb
+++ b/meta/recipes-extended/logrotate/logrotate_3.15.1.bb
@@ -22,6 +22,9 @@ SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/${PV}/${BP}.tar.xz
 SRC_URI[md5sum] = "afe109afea749c306ff489203fde6beb"
 SRC_URI[sha256sum] = "491fec9e89f1372f02a0ab66579aa2e9d63cac5178dfa672c204c88e693a908b"
 
+# These CVEs are debian, gentoo or SUSE specific on the way logrotate was installed/used
+CVE_CHECK_WHITELIST += "CVE-2011-1548 CVE-2011-1549 CVE-2011-1550"
+
 PACKAGECONFIG ?= "${@bb.utils.filter('DISTRO_FEATURES', 'acl selinux', d)}"
 
 PACKAGECONFIG[acl] = ",,acl"
-- 
2.25.1


  parent reply	other threads:[~2021-05-12 14:58 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-05-12 14:56 [OE-core][dunfell 00/22] Patch review Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 01/22] subversion: fix CVE-2020-17525 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 02/22] qemu: fix CVE-2021-3392 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 03/22] tiff: fix CVE-2020-35523 CVE-2020-35524 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 04/22] python3-jinja2: 2.11.2 -> 2.11.3 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 05/22] glibc: Document and whitelist CVE-2019-1010022-25 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 06/22] cairo: backport patch for CVE-2020-35492 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 07/22] libnotify: whitelist CVE-2013-7381 (specific to the NodeJS bindings) Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 08/22] builder: whitelist CVE-2008-4178 (a different builder) Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 09/22] qemu: Exclude CVE-2017-5957 from cve-check Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 10/22] qemu: Exclude CVE-2007-0998 " Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 11/22] qemu: Exclude CVE-2018-18438 " Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 12/22] jquery: Exclude CVE-2007-2379 " Steve Sakoman
2021-05-12 14:56 ` Steve Sakoman [this message]
2021-05-12 14:56 ` [OE-core][dunfell 14/22] openssh: Exclude CVE-2007-2768 " Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 15/22] oeqa/qemurunner: Fix binary vs str issue Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 16/22] oeqa/qemurunner: Improve handling of run_serial for shutdown commands Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 17/22] lsb-release: fix reproducibility failure Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 18/22] db: update CVE_PRODUCT Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 19/22] linux-firmware: upgrade 20210208 -> 20210315 Steve Sakoman
2021-05-12 14:56 ` [OE-core][dunfell 20/22] linux-yocto/5.4: qemuppc32: reduce serial shutdown issues Steve Sakoman
2021-05-12 14:57 ` [OE-core][dunfell 21/22] dejagnu: needs expect at runtime Steve Sakoman
2021-05-12 14:57 ` [OE-core][dunfell 22/22] linux-firmware: include all relevant files in -bcm4356 Steve Sakoman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7222f10e99e5a345c68feb254d309e55024ef4aa.1620831171.git.steve@sakoman.com \
    --to=steve@sakoman.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.