mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-09 07:51:59 -09:00
53a8616460e5730abe703ca5a46bae0039d548aa
Setting the "update" field in the CPE ID to * doesn't actually make much sense, as * is a wildcard. Instead, this field should really reflect the "subrelease" / "update" of the package, which unless specified explicitly by the package .mk file, is empty. Using a wildcard causes a few CVEs to be incorrectly identified as affecting some of our packages. For example https://nvd.nist.gov/vuln/detail/CVE-2013-1428 has a CPE configuration that goes like this: cpe:2.3:a:tinc-vpn:tinc:*:pre6:*:*:*:*:*:* up to including 1.1 and this CPE configuration is currently identified as affecting our package. This isn't correct as our package is using 1.0.36, not a "pre6" version. But because the CPE ID generated by Buildroot uses * as the "update" field, and * is the wildcard, it does match with this CPE configuration. After this change, two CVEs are no longer identified as affecting Buildroot packages: https://nvd.nist.gov/vuln/detail/CVE-2013-1428 https://nvd.nist.gov/vuln/detail/CVE-2017-9454 and in both cases they are indeed CVEs not affecting our package. Reported-by: Titouan Christophe <titouan.christophe@mind.be> Cc: Titouan Christophe <titouan.christophe@mind.be> Cc: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> Reviewed-by: Titouan Christophe <titouan.christophe@mind.be> Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
…
…
…
Buildroot is a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation. The documentation can be found in docs/manual. You can generate a text document with 'make manual-text' and read output/docs/manual/manual.text. Online documentation can be found at http://buildroot.org/docs.html To build and use the buildroot stuff, do the following: 1) run 'make menuconfig' 2) select the target architecture and the packages you wish to compile 3) run 'make' 4) wait while it compiles 5) find the kernel, bootloader, root filesystem, etc. in output/images You do not need to be root to build or run buildroot. Have fun! Buildroot comes with a basic configuration for a number of boards. Run 'make list-defconfigs' to view the list of provided configurations. Please feed suggestions, bug reports, insults, and bribes back to the buildroot mailing list: buildroot@buildroot.org You can also find us on #buildroot on OFTC IRC. If you would like to contribute patches, please read https://buildroot.org/manual.html#submitting-patches
Description
Languages
Makefile
62.5%
Python
19%
C
8.5%
Shell
6.1%
PHP
1.4%
Other
2.1%