Files
buildroot/package
Quentin Schulz cb419c8b3c package/busybox: fix CVE-2022-28391
The patches have been used by Alpine for 5 months now and they were
posted on the Busybox mailing list mid-July with no review or comment.

According to Ariadne Conill[1] - though NVD CVSS 3.x Base Score seems to
disagree - this has a low security impact so we could probably just wait
for upstream to merge the patches or implement it the way they want.

Considering those patches have been public for 5 months and upstream
hasn't acted until now, let's take the patches from the mailing list
anyway as there's no indication the CVEs will be fixed upstream soon.

[1] https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661

Cc: Quentin Schulz <foss+buildroot@0leil.net>
Signed-off-by: Quentin Schulz <quentin.schulz@theobroma-systems.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
(cherry picked from commit 4a03d17172)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2022-09-29 22:06:40 +02:00
..
2022-08-10 17:05:35 +02:00
2022-09-14 22:57:26 +02:00
2022-09-18 10:49:42 +02:00
2022-09-29 15:52:05 +02:00
2022-09-15 09:27:26 +02:00
2022-07-19 19:03:30 +02:00
2022-08-18 08:13:07 +02:00
2022-08-16 23:26:42 +02:00
2022-08-08 16:28:38 +02:00
2022-09-15 19:07:15 +02:00
2022-08-16 08:42:17 +02:00
2022-08-16 08:39:10 +02:00
2022-09-17 22:22:35 +02:00
2022-09-15 09:35:08 +02:00
2022-06-19 15:46:21 +02:00
2022-09-15 00:22:58 +02:00
2022-09-21 22:40:02 +02:00
2022-09-16 12:15:44 +02:00
2022-09-16 12:15:49 +02:00
2022-07-19 17:03:58 +02:00
2022-09-17 10:11:12 +02:00
2022-08-11 13:50:28 +02:00
2022-08-14 21:01:31 +02:00