]> code.ossystems Code Review - openembedded-core.git/commitdiff
openssl: Whitelist CVE-2019-0190
authorAdrian Bunk <bunk@stusta.de>
Thu, 5 Dec 2019 21:42:27 +0000 (23:42 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 31 Dec 2019 10:36:31 +0000 (10:36 +0000)
This is only a problem with older Apache versions.

(From OE-Core rev: 492d43296b15514ec72dfb15f37c6d2ab1fbbae3)

Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-connectivity/openssl/openssl_1.1.1d.bb

index 9fe80e5fd20e54d6c36c859c6f50f48935749d93..458ae7daf4e6a9aa73dcbc3745762b118ad8384a 100644 (file)
@@ -203,3 +203,7 @@ RDEPENDS_${PN}-ptest += "openssl-bin perl perl-modules bash"
 BBCLASSEXTEND = "native nativesdk"
 
 CVE_PRODUCT = "openssl:openssl"
+
+# Only affects OpenSSL >= 1.1.1 in combination with Apache < 2.4.37
+# Apache in meta-webserver is already recent enough
+CVE_CHECK_WHITELIST += "CVE-2019-0190"