mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-08-12 17:38:20 +00:00
quagga: ignore CVE-2021-44038
Details: https://nvd.nist.gov/vuln/detail/CVE-2021-44038 The main point of the vulnerability is that the application comes with its own systemd unit files, which execute chmod and chown commands upon start on some files. So when the services are restarted (e.g. after an update), these unit files can be tricked to change the permissions on a malicious file. However OE does not use these unit files - the recipe comes with its own custom unit files, and chown/chmod isn't used at all. Due to this, ignore this vulnerability. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
This commit is contained in:
parent
3054edf8bb
commit
b3c43cc096
@ -5,4 +5,5 @@ SRC_URI[sha256sum] = "e364c082c3309910e1eb7b068bf39ee298e2f2f3f31a6431a5c115193b
|
||||
|
||||
CVE_CHECK_IGNORE += "\
|
||||
CVE-2016-4049 \
|
||||
CVE-2021-44038 \
|
||||
"
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user