| Summary: | curl: multiple CVEs; CVE-2016-8615 /25 | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] Security - Recipe Upgrade | Reporter: | Sona Sarmadi <sona.sarmadi> |
| Component: | security | Assignee: | Saul Wold <sgw> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Undecided | CC: | akuster, richard.purdie |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Sona Sarmadi
2016-11-08 07:49:32 UTC
Patch sent to master: https://patchwork.openembedded.org/patch/133682/ I will send patches to morty & krogoth soon. curl 7.51.0-r0 address all these CVEs. A patch for master has been sent to upgrade curl to 7.51.0-r0. I wonder if we can upgrade krogoth and morty to 7.51.0-r0 as well? Both package versions are using same libcurl.so version i.e. libcurl.so.4.4.0: tmp/work/i586-poky-linux/curl/7.47.1-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0 tmp/work/i586-poky-linux/curl/7.51.0-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0 Patch sent to master is applicable for morty branch as well. Patches sent for krogoth. in krogoth. http://cgit.openembedded.org/openembedded-core/commit/?h=krogoth&id=bf8d4e9c8a7fed4e190d600a6a26d314d4b15a08 '' http://cgit.openembedded.org/openembedded-core/commit/?h=krogoth&id=ba4e218d1e09aaecbdb760a299826c03202a9ba9 http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=morty&id=6131edc2c9de3d2fe03243a423e2441a6ec855ce and preceeding commits, so all maintained stable branches are fixed. |