Bug 2685

Summary: Recipe security upgrades for 1.2.2
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Scott Garman <scott.a.garman>
Component: coreAssignee: Scott Garman <scott.a.garman>
Status: RESOLVED INVALID QA Contact:
Severity: normal    
Priority: Medium CC: jessica.zhang, meta.mr.watcher, meta.watcher
Version: 1.2.1   
Target Milestone: 1.2.2   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: ---

Description Scott Garman 2012-07-03 17:06:54 UTC
It's too late to get these into 1.2.1, but these recipes will need to get upgraded for 1.2.2:

openssl:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333

libpng:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3048

xinetd:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0862

libxml2:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1025
Comment 1 Jessica 2012-07-05 14:43:08 UTC
Please file 4 separate bugs since each pacakge is owned by different people
Comment 2 Scott Garman 2012-07-05 15:15:18 UTC
I've now filed separate bugs for these, so I'm closing this one.

openssl - bug #2701

xinetd - bug #2702

libxml2 - bug #2703

I was mistaken about libpng, the version we ship is actually safe.