python: Whitelist CVE-2017-17522 CVE-2017-18207 CVE-2015-5652

Submitted by Adrian Bunk on Dec. 5, 2019, 7:28 p.m. | Patch ID: 167675

Details

Message ID 20191205192814.18201-1-bunk@stusta.de
State Superseded
Commit 56d5b181f3b119f2bbd310dedd6d3b26e76f5944
Headers show

Commit Message

Adrian Bunk Dec. 5, 2019, 7:28 p.m.
One Windows-only CVE that cannot be fixed, and two CVEs
where upstream agreement is that they are not vulnerabilities.

Signed-off-by: Adrian Bunk <bunk@stusta.de>
---
 meta/recipes-devtools/python/python.inc | 10 ++++++++++
 1 file changed, 10 insertions(+)

Patch hide | download patch | download mbox

diff --git a/meta/recipes-devtools/python/python.inc b/meta/recipes-devtools/python/python.inc
index a630c26e89..110ec315d9 100644
--- a/meta/recipes-devtools/python/python.inc
+++ b/meta/recipes-devtools/python/python.inc
@@ -19,6 +19,16 @@  UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>2(\.\d+)+).tar"
 
 CVE_PRODUCT = "python"
 
+# Upstream agreement is that these are not security issues:
+# https://bugs.python.org/issue32367
+CVE_CHECK_WHITELIST += "CVE-2017-17522"
+# https://bugs.python.org/issue32056
+CVE_CHECK_WHITELIST += "CVE-2017-18207"
+
+# Windows-only, "It was determined that this is a longtime behavior
+# of Python that cannot really be altered at this point."
+CVE_CHECK_WHITELIST += "CVE-2015-5652"
+
 PYTHON_MAJMIN = "2.7"
 
 inherit autotools pkgconfig

Comments

Adrian Bunk Jan. 18, 2020, 4:04 a.m.
This is a system generated Comment: Patch 167675 was automatically marked as superseded by patch 169053.