mirror of
https://git.yoctoproject.org/poky
synced 2026-04-05 08:02:25 +02:00
tiff: Exclude CVE-2015-7313 from cve-check
Some fix upstream addresses the issue, it isn't clear which change this was. Our current version doesn't have issues with the test image though so we can exclude. (From OE-Core rev: 256f6be93eed82c7db8a76b1038e105331c0009f) Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 3874da694ae1d9de06dd003bd80705205e2b033b) Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
@@ -19,6 +19,10 @@ SRC_URI[sha256sum] = "5d29f32517dadb6dbcd1255ea5bbc93a2b54b94fbf83653b4d65c7d677
|
||||
# exclude betas
|
||||
UPSTREAM_CHECK_REGEX = "tiff-(?P<pver>\d+(\.\d+)+).tar"
|
||||
|
||||
# Tested with check from https://security-tracker.debian.org/tracker/CVE-2015-7313
|
||||
# and 4.1.0 doesn't have the issue
|
||||
CVE_CHECK_WHITELIST += "CVE-2015-7313"
|
||||
|
||||
inherit autotools multilib_header
|
||||
|
||||
CACHED_CONFIGUREVARS = "ax_cv_check_gl_libgl=no"
|
||||
|
||||
Reference in New Issue
Block a user