]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
libmicrohttpd: set status for CVE-2025-59777 and CVE-2025-62689
authorPeter Marko <peter.marko@siemens.com>
Wed, 29 Apr 2026 19:36:43 +0000 (21:36 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 6 May 2026 13:02:21 +0000 (14:02 +0100)
This was fixed in the same commit includeded in 1.0.3 per [1] and [2].
The CVEs have dates instead of version in CPE.

[1] https://security-tracker.debian.org/tracker/CVE-2025-59777
[2] https://security-tracker.debian.org/tracker/CVE-2025-62689

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-support/libmicrohttpd/libmicrohttpd_1.0.5.bb

index cca3496a19f2039b66ddf1dd011fbd933cd7ba5d..935fbfcf89d22c8e66da9925b760f66c0391e375 100644 (file)
@@ -25,3 +25,6 @@ do_compile:append() {
 }
 
 BBCLASSEXTEND = "native nativesdk"
+
+CVE_STATUS[CVE-2025-59777] = "fixed-version: fixed since 1.0.3"
+CVE_STATUS[CVE-2025-62689] = "fixed-version: fixed since 1.0.3"