]> code.ossystems Code Review - openembedded-core.git/commit
xserver-xorg: whitelist two CVEs
authorRoss Burton <ross@burtonini.com>
Mon, 10 Jan 2022 12:19:32 +0000 (12:19 +0000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 12 Jan 2022 14:37:31 +0000 (04:37 -1000)
commitc477e35d01e7b8443b680f6456ac92a15fbfeaa2
treee6eb105d043af7c52cfb22c428d154b3b69db73d
parent022750aaa128189f23063b741bf8396a527713d7
xserver-xorg: whitelist two CVEs

CVE-2011-4613 is specific to Debian/Ubuntu.

CVE-2020-25697 is a non-trivial attack that may not actually be feasible
considering the default behaviour for clients is to exit if the
connection is lost.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit afa2e6c31a79f75ff4113d53f618bbb349cd6c17)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/xorg-xserver/xserver-xorg.inc