Re: [OE-core] [PATCH v2] file: add CVE_PRODUCT

2024-03-23 Thread Emil Kronborg via lists.openembedded.org
On Thu, Mar 21, 2024 at 17:15 +, Ross Burton wrote: > There’s also file:file, for example > https://nvd.nist.gov/vuln/detail/CVE-2007-2799. Hm, clicking on "Show Matching CPE(s)" gives no matches, which a search also confirms. Searching for file_project:file yield results with identical

Re: [OE-core] [PATCH v2] file: add CVE_PRODUCT

2024-03-21 Thread Ross Burton
On 20 Mar 2024, at 16:08, Emil Kronborg via lists.openembedded.org wrote: > > Having only file as the CVE product is too generic. What we actually > want is file from file_project to match the correct CVE(s). There’s also file:file, for example https://nvd.nist.gov/vuln/detail/CVE-2007-2799.

[OE-core] [PATCH v2] file: add CVE_PRODUCT

2024-03-20 Thread Emil Kronborg via lists.openembedded.org
Having only file as the CVE product is too generic. What we actually want is file from file_project to match the correct CVE(s). Signed-off-by: Emil Kronborg --- Changes in v2: - I forgot to sign the first version. meta/recipes-devtools/file/file_5.45.bb | 2 ++ 1 file changed, 2 insertions(+)