mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-09 17:03:35 -09:00
package/rsyslog: remove stale IGNORE_CVES
Since Buildroot commit [1] the CVEs are no longer matched to CPEs with versions using '-'. The CVE-2015-3243 is then no longer matched to the rsyslog package. For more information, see the explanation in commit [1]. [1]35f376d88esupport/scripts/cve.py: fix CPE matching Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> (cherry picked from commit1e48fde1cb) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
@@ -9,10 +9,6 @@ RSYSLOG_SITE = http://rsyslog.com/files/download/rsyslog
|
||||
RSYSLOG_LICENSE = GPL-3.0, LGPL-3.0, Apache-2.0
|
||||
RSYSLOG_LICENSE_FILES = COPYING COPYING.LESSER COPYING.ASL20
|
||||
RSYSLOG_CPE_ID_VENDOR = rsyslog
|
||||
# rsyslog uses weak permissions for generating log files.
|
||||
# Ignoring this CVE as Buildroot normally doesn't have local users and a build
|
||||
# could customize the rsyslog.conf to be more restrictive ($FileCreateMode 0640)
|
||||
RSYSLOG_IGNORE_CVES += CVE-2015-3243
|
||||
RSYSLOG_DEPENDENCIES = zlib libestr liblogging libfastjson host-pkgconf
|
||||
RSYSLOG_CONF_ENV = ac_cv_prog_cc_c99='-std=c99'
|
||||
|
||||
|
||||
Reference in New Issue
Block a user