diff options
author | Adrian Bunk <bunk@stusta.de> | 2020-01-17 19:04:20 +0200 |
---|---|---|
committer | Armin Kuster <akuster808@gmail.com> | 2020-01-22 18:14:57 -0800 |
commit | 1b69d141b73e46cc377f8566868da44dd5b1ea42 (patch) | |
tree | 93537be04d7f7150712bfa918109397c8b94b2c3 | |
parent | 279c4da2e5f46dccfeff0c898c2205940be9e174 (diff) | |
download | openembedded-core-contrib-1b69d141b73e46cc377f8566868da44dd5b1ea42.tar.gz |
python: Whitelist CVE-2017-17522 CVE-2017-18207 CVE-2015-5652
One Windows-only CVE that cannot be fixed, and two CVEs
where upstream agreement is that they are not vulnerabilities.
Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r-- | meta/recipes-devtools/python/python.inc | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/meta/recipes-devtools/python/python.inc b/meta/recipes-devtools/python/python.inc index b093ea6f09..5d280dc63b 100644 --- a/meta/recipes-devtools/python/python.inc +++ b/meta/recipes-devtools/python/python.inc @@ -19,6 +19,16 @@ UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>2(\.\d+)+).tar" CVE_PRODUCT = "python" +# Upstream agreement is that these are not security issues: +# https://bugs.python.org/issue32367 +CVE_CHECK_WHITELIST += "CVE-2017-17522" +# https://bugs.python.org/issue32056 +CVE_CHECK_WHITELIST += "CVE-2017-18207" + +# Windows-only, "It was determined that this is a longtime behavior +# of Python that cannot really be altered at this point." +CVE_CHECK_WHITELIST += "CVE-2015-5652" + PYTHON_MAJMIN = "2.7" inherit autotools pkgconfig |