]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
curl: ignore CVE-2023-42915
authorPeter Marko <peter.marko@siemens.com>
Thu, 1 Feb 2024 22:51:13 +0000 (23:51 +0100)
committerSteve Sakoman <steve@sakoman.com>
Fri, 2 Feb 2024 14:43:42 +0000 (04:43 -1000)
This CVE reports that apple had to upgrade curl because of other
already reported CVEs:
* CVE-2023-38039: not affected, introduced in 7.84.0
* CVE-2023-38545: patch already backported
* CVE-2023-38546: patch already backported
* CVE-2023-42915: reference to itself

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-support/curl/curl_7.69.1.bb

index a8e6c4f3ee1fcaa4947d0537670ef781f11972a4..980b4224a8cf65808592ae7fa5ff16b6320f88e5 100644 (file)
@@ -72,6 +72,9 @@ CVE_CHECK_WHITELIST = "CVE-2021-22922 CVE-2021-22923 CVE-2021-22926 CVE-2021-229
 # This CVE issue affects Windows only Hence whitelisting this CVE
 CVE_CHECK_WHITELIST += "CVE-2021-22897"
 
+# This CVE reports that apple had to upgrade curl because of other already reported CVEs
+CVE_CHECK_WHITELIST += "CVE-2023-42915"
+
 inherit autotools pkgconfig binconfig multilib_header
 
 PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)} gnutls libidn proxy threaded-resolver verbose zlib"