[OE-core] [PATCH 0/1] nss: CVE-2014-1568

akuster808 akuster808 at gmail.com
Wed Nov 12 05:54:45 UTC 2014


Would I upgrade nss for dizzy or backport the cve fix (leaning towards 
back porting).

- armin

On 11/07/2014 04:34 PM, Burton, Ross wrote:
> Hi Chong,
>
> On 6 November 2014 07:50, Chong Lu <Chong.Lu at windriver.com
> <mailto:Chong.Lu at windriver.com>> wrote:
>
>     The following changes since commit
>     0add8abc12b850e38a6ec7dcf2856fab2c0107b6:
>
>        buildtools-tarball: package all of Python (2014-11-05 23:30:49 +0000)
>
>     are available in the git repository at:
>
>        git://git.pokylinux.org/poky-contrib
>     <http://git.pokylinux.org/poky-contrib> chonglu/nss
>     http://git.pokylinux.org/cgit.cgi/poky-contrib/log/?h=chonglu/nss
>
>     Chong Lu (1):
>        nss: CVE-2014-1568
>
>
> Sorry, but we've just merged Saul's upgrade of NSS to 3.17 so this
> doesn't apply, and as we're unfrozen now an upgrade to the fixed 3.17.1
> seems like the sensible way forwards.  Could you do this upgrade?
>
> Ross
>
>



More information about the Openembedded-core mailing list