python: Whitelist CVE-2017-17522 CVE-2017-18207 CVE-2015-5652

One Windows-only CVE that cannot be fixed, and two CVEs
where upstream agreement is that they are not vulnerabilities.

(From OE-Core rev: 56d5b181f3b119f2bbd310dedd6d3b26e76f5944)

Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Adrian Bunk
2019-12-05 21:28:13 +02:00
committed by Richard Purdie
parent e68e623ef3
commit 5e4a1b0842

View File

@@ -19,6 +19,16 @@ UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>2(\.\d+)+).tar"
CVE_PRODUCT = "python"
# Upstream agreement is that these are not security issues:
# https://bugs.python.org/issue32367
CVE_CHECK_WHITELIST += "CVE-2017-17522"
# https://bugs.python.org/issue32056
CVE_CHECK_WHITELIST += "CVE-2017-18207"
# Windows-only, "It was determined that this is a longtime behavior
# of Python that cannot really be altered at this point."
CVE_CHECK_WHITELIST += "CVE-2015-5652"
PYTHON_MAJMIN = "2.7"
inherit autotools pkgconfig