| Summary: | libarchive has open CVEs: CVE-2015-2304, CVE-2013-0211 | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Elena Reshetova <elena.reshetova> |
| Component: | core | Assignee: | Ross Burton <ross.burton> |
| Status: | RESOLVED OBSOLETE | QA Contact: | |
| Severity: | normal | ||
| Priority: | Undecided | CC: | meta.mr.watcher, meta.watcher |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Elena Reshetova
2015-10-30 07:13:24 UTC
2013-0211 is in git already: http://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/recipes-extended/libarchive/libarchive/libarchive-CVE-2013-0211.patch Also 2015-2304 is fixed in "0001-Add-ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS-option.patch". I get why the 2015-2304 wasn't detected by whatever CVE scanning tool you are using, but I do wonder why 2012-0211 wasn't detected as it has the CVE name in the filename. That's a good question. I will investigate why it wasn't detected. Now we have a first real case, so it helps. Actually I checked this one and the fault is not on the tool side but on the reporter side (me :)). Tool correctly detected that there are two CVEs, but marked one as patched (2013 one), but since the difference in cve-check.tool reporting is only comma vs. space, I didn't notice it and reported both. Would it be possible to rename the patch for 2015 CVE also to somehow reflect that it fixes cve? Yes, I'll send a rename patch for master. Thank you very much! |