This patch is useful to go around CVE-2019-5953 but other versions of poky, like the thud do not have the correction.
Should this version bump be backported or the patch http://git.savannah.gnu.org/cgit/wget.git/commit/?id=692d5c5215de0db482c252492a92fc424cc6a97c be applied in older versions? On Wed, Apr 24, 2019 at 8:56 AM Oleksandr Kravchuk <[email protected]> wrote: > > Signed-off-by: Oleksandr Kravchuk <[email protected]> > --- > meta/recipes-extended/wget/wget_1.20.2.bb | 8 -------- > meta/recipes-extended/wget/wget_1.20.3.bb | 8 ++++++++ > 2 files changed, 8 insertions(+), 8 deletions(-) > delete mode 100644 meta/recipes-extended/wget/wget_1.20.2.bb > create mode 100644 meta/recipes-extended/wget/wget_1.20.3.bb > > diff --git a/meta/recipes-extended/wget/wget_1.20.2.bb > b/meta/recipes-extended/wget/wget_1.20.2.bb > deleted file mode 100644 > index cd20785259..0000000000 > --- a/meta/recipes-extended/wget/wget_1.20.2.bb > +++ /dev/null > @@ -1,8 +0,0 @@ > -SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ > - file://0002-improve-reproducibility.patch \ > - " > - > -SRC_URI[md5sum] = "2692f6678e93601441306b5c1fc6a77a" > -SRC_URI[sha256sum] = > "7e43b98cb5e10234836ebef6faf24c4d96c0ae7a480e49ff658117cc4793d166" > - > -require wget.inc > diff --git a/meta/recipes-extended/wget/wget_1.20.3.bb > b/meta/recipes-extended/wget/wget_1.20.3.bb > new file mode 100644 > index 0000000000..4fa273d093 > --- /dev/null > +++ b/meta/recipes-extended/wget/wget_1.20.3.bb > @@ -0,0 +1,8 @@ > +SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ > + file://0002-improve-reproducibility.patch \ > + " > + > +SRC_URI[md5sum] = "db4e6dc7977cbddcd543b240079a4899" > +SRC_URI[sha256sum] = > "31cccfc6630528db1c8e3a06f6decf2a370060b982841cfab2b8677400a5092e" > + > +require wget.inc > -- > 2.17.1 > > -- > _______________________________________________ > Openembedded-core mailing list > [email protected] > http://lists.openembedded.org/mailman/listinfo/openembedded-core -- _______________________________________________ Openembedded-core mailing list [email protected] http://lists.openembedded.org/mailman/listinfo/openembedded-core
