mbox series

[meta-oe,00/12] ignore or mark fixed several CVEs

Message ID 20241219202423.346033-1-peter.marko@siemens.com
Headers show
Series ignore or mark fixed several CVEs | expand

Message

Marko, Peter Dec. 19, 2024, 8:24 p.m. UTC
This series handles all CVEs in meta-openembedded master report which I
think that can be removed from reports without doing an upgrade or patch.

Peter Marko (12):
  ace: ignore CVE-2009-1147
  apache2: ignore CVE-1999-0678 and CVE-1999-1412
  apache2: remove old version references from CVEs
  spice: ignore CVE-2016-0749
  gattlib: mark CVE-2019-6498 as fixed
  monkey: ignore CVE-2013-1771
  redis: ignore CVE-2022-0543
  spice-gtk: mark CVE-2012-4425 as fixed
  apache2: ignore disputed CVE CVE-2007-0086
  swagger-ui: mark CVE-2016-1000229 as fixed
  memcached: ignore disputed CVE-2022-26635
  emlog: set CVE_PRODUCT

 .../memcached/memcached_1.6.17.bb               |  2 ++
 .../recipes-support/spice/spice-gtk_0.42.bb     |  2 ++
 .../recipes-support/spice/spice_git.bb          |  1 +
 meta-oe/recipes-connectivity/ace/ace_8.0.1.bb   |  2 ++
 .../recipes-connectivity/gattlib/gattlib_git.bb |  2 ++
 meta-oe/recipes-core/emlog/emlog.inc            |  2 ++
 meta-oe/recipes-extended/redis/redis_7.2.6.bb   |  1 +
 .../swagger-ui/swagger-ui_5.18.2.bb             |  2 ++
 .../recipes-httpd/apache2/apache2_2.4.62.bb     | 17 ++++++++++-------
 .../recipes-httpd/monkey/monkey_1.6.9.bb        |  1 +
 10 files changed, 25 insertions(+), 7 deletions(-)