mirror of
https://git.yoctoproject.org/poky
synced 2026-02-07 01:06:37 +01:00
python: Whitelist CVE-2017-17522 CVE-2017-18207 CVE-2015-5652
One Windows-only CVE that cannot be fixed, and two CVEs where upstream agreement is that they are not vulnerabilities. (From OE-Core rev: 56d5b181f3b119f2bbd310dedd6d3b26e76f5944) (From OE-Core rev: 13024049625c1705108066b38396ac379aacce84) Signed-off-by: Adrian Bunk <bunk@stusta.de> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Anuj Mittal <anuj.mittal@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
cd46d6826d
commit
8f8a76d319
@@ -19,6 +19,16 @@ UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>2(\.\d+)+).tar"
|
||||
|
||||
CVE_PRODUCT = "python"
|
||||
|
||||
# Upstream agreement is that these are not security issues:
|
||||
# https://bugs.python.org/issue32367
|
||||
CVE_CHECK_WHITELIST += "CVE-2017-17522"
|
||||
# https://bugs.python.org/issue32056
|
||||
CVE_CHECK_WHITELIST += "CVE-2017-18207"
|
||||
|
||||
# Windows-only, "It was determined that this is a longtime behavior
|
||||
# of Python that cannot really be altered at this point."
|
||||
CVE_CHECK_WHITELIST += "CVE-2015-5652"
|
||||
|
||||
PYTHON_MAJMIN = "2.7"
|
||||
|
||||
inherit autotools pkgconfig
|
||||
|
||||
Reference in New Issue
Block a user