Whitelisted below CVEs as their status is disputed and ignored and not affecting the Ubuntu and Debian environments. Hence, marked them whitelisted.
1. CVE-2018-12433 Link: https://security-tracker.debian.org/tracker/CVE-2018-12433 2. CVE-2018-12438 Link: https://security-tracker.debian.org/tracker/CVE-2018-12438 Signed-off-by: Saloni Jain <[email protected]> --- meta/recipes-support/libgcrypt/libgcrypt_1.8.5.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-support/libgcrypt/libgcrypt_1.8.5.bb b/meta/recipes-support/libgcrypt/libgcrypt_1.8.5.bb index 4e0eb0a..ba3666f 100644 --- a/meta/recipes-support/libgcrypt/libgcrypt_1.8.5.bb +++ b/meta/recipes-support/libgcrypt/libgcrypt_1.8.5.bb @@ -29,6 +29,9 @@ SRC_URI = "${GNUPG_MIRROR}/libgcrypt/libgcrypt-${PV}.tar.bz2 \ SRC_URI[md5sum] = "348cc4601ca34307fc6cd6c945467743" SRC_URI[sha256sum] = "3b4a2a94cb637eff5bdebbcaf46f4d95c4f25206f459809339cdada0eb577ac3" +# Below whitelisted CVEs are disputed and not affecting Ubuntu and Debian environments. +CVE_CHECK_WHITELIST += "CVE-2018-12433 CVE-2018-12438" + BINCONFIG = "${bindir}/libgcrypt-config" inherit autotools texinfo binconfig-disabled pkgconfig -- 2.7.4 This message contains information that may be privileged or confidential and is the property of the KPIT Technologies Ltd. It is intended only for the person to whom it is addressed. If you are not the intended recipient, you are not authorized to read, print, retain copy, disseminate, distribute, or use this message or any part thereof. If you receive this message in error, please notify the sender immediately and delete all copies of this message. KPIT Technologies Ltd. does not accept any liability for virus infected mails.
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#147584): https://lists.openembedded.org/g/openembedded-core/message/147584 Mute This Topic: https://lists.openembedded.org/mt/80321678/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
