[OE-core] [PATCH] bind: Whitelist CVE-2019-6470

Adrian Bunk bunk at stusta.de
Thu Nov 14 12:51:01 UTC 2019


On Thu, Nov 14, 2019 at 12:04:40PM +0000, Ross Burton wrote:
> On 13/11/2019 08:19, Adrian Bunk wrote:
> > +# Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later
> > +CVE_CHECK_WHITELIST += "CVE-2019-6470"
> 
> Can you be a bit more explicit about why this is whitelisted?

Something like
  BIND >= 9.11.2 need dhcpd >= 4.4.1, don't report it here since
  dhcpd is already recent enough.
?

> Ross

cu
Adrian

-- 

       "Is there not promise of rain?" Ling Tan asked suddenly out
        of the darkness. There had been need of rain for many days.
       "Only a promise," Lao Er said.
                                       Pearl S. Buck - Dragon Seed



More information about the Openembedded-core mailing list