Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-27 Thread Richard Purdie
On Fri, 2023-01-27 at 12:57 +, Richard Purdie wrote: > On Mon, 2023-01-23 at 13:41 +, Ross Burton wrote: > > On 23 Jan 2023, at 13:35, Richard Purdie > > wrote: > > > > I’ve started braindumping into > > > > https://wiki.yoctoproject.org/wiki/CVE_Triage, when it’s expanded and > > > >

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-27 Thread Richard Purdie
On Mon, 2023-01-23 at 13:41 +, Ross Burton wrote: > On 23 Jan 2023, at 13:35, Richard Purdie > wrote: > > > I’ve started braindumping into > > > https://wiki.yoctoproject.org/wiki/CVE_Triage, when it’s expanded and > > > complete we can link to it. Or maybe we should just start a > > >

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-25 Thread Michael Opdenacker via lists.openembedded.org
On 23.01.23 at 14:41, Ross Burton wrote: On 23 Jan 2023, at 13:35, Richard Purdie wrote: I’ve started braindumping into https://wiki.yoctoproject.org/wiki/CVE_Triage, when it’s expanded and complete we can link to it. Or maybe we should just start a Maintainers book in the documentation?

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Richard Purdie
On Mon, 2023-01-23 at 13:29 +, Ross Burton wrote: > On 23 Jan 2023, at 12:42, Alexander Kanavin wrote: > > > > On Mon, 23 Jan 2023 at 13:40, Ross Burton wrote: > > > > CVE-2022-3550 (CVSS3: 8.8 HIGH): xserver-xorg > > > > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 * > >

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Ross Burton
On 23 Jan 2023, at 13:35, Richard Purdie wrote: >> I’ve started braindumping into >> https://wiki.yoctoproject.org/wiki/CVE_Triage, when it’s expanded and >> complete we can link to it. Or maybe we should just start a >> Maintainers book in the documentation? > > Lets put it in the manual. The

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Richard Purdie
On Mon, 2023-01-23 at 13:29 +, Ross Burton wrote: > On 23 Jan 2023, at 12:42, Alexander Kanavin wrote: > > > > On Mon, 23 Jan 2023 at 13:40, Ross Burton wrote: > > > > CVE-2022-3550 (CVSS3: 8.8 HIGH): xserver-xorg > > > > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 * > >

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Ross Burton
On 23 Jan 2023, at 12:42, Alexander Kanavin wrote: > > On Mon, 23 Jan 2023 at 13:40, Ross Burton wrote: >>> CVE-2022-3550 (CVSS3: 8.8 HIGH): xserver-xorg >>> https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 * >>> CVE-2022-3551 (CVSS3: 6.5 MEDIUM): xserver-xorg >>>

Re: [yocto-security] [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Alexander Kanavin
On Mon, 23 Jan 2023 at 13:40, Ross Burton wrote: > > CVE-2022-3550 (CVSS3: 8.8 HIGH): xserver-xorg > > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 * > > CVE-2022-3551 (CVSS3: 6.5 MEDIUM): xserver-xorg > > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3551 * > >

Re: [OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-23 Thread Ross Burton
On 22 Jan 2023, at 12:04, Steve Sakoman via lists.openembedded.org wrote: > CVE-2022-3550 (CVSS3: 8.8 HIGH): xserver-xorg > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 * > CVE-2022-3551 (CVSS3: 6.5 MEDIUM): xserver-xorg >

[OE-core] OE-core CVE metrics for master on Sun 22 Jan 2023 02:00:01 AM HST

2023-01-22 Thread Steve Sakoman
Branch: master New this week: 0 CVEs Removed this week: 3 CVEs CVE-2023-0049 (CVSS3: 7.8 HIGH): vim https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0049 * CVE-2023-0051 (CVSS3: 7.8 HIGH): vim https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0051 * CVE-2023-0054 (CVSS3: 7.8