From: Devansh Patel <[email protected]> The current pycryptodome:pycryptodomex mapping is an active NVD dictionary CPE and NVD vulnerability-configuration identity. It reaches CVE-2023-52323 but misses CVE-2018-15560, whose NVD configuration uses pycryptodome:pycryptodome, another active dictionary CPE.
PyCryptodome and PyCryptodomex are built from the same upstream source, and the affected AESNI source is also shipped by PyCryptodomex. Add the shared active identity while retaining the existing dedicated identity. This makes CVE-2018-15560 properly report as patched. Signed-off-by: Devansh Patel <[email protected]> --- meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb index 148409c8d9..e2120d9972 100644 --- a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb +++ b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb @@ -3,7 +3,7 @@ inherit python_setuptools_build_meta SRC_URI[sha256sum] = "71909758f010c82bc99b0abf4ea12012c98962fbf0583c2164f8b84533c2e4da" -CVE_PRODUCT = "pycryptodome:pycryptodomex" +CVE_PRODUCT = "pycryptodome:pycryptodome pycryptodome:pycryptodomex" FILES:${PN}-tests = " \ ${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/ \ -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243846): https://lists.openembedded.org/g/openembedded-core/message/243846 Mute This Topic: https://lists.openembedded.org/mt/120843302/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
