Bug 2685 - Recipe security upgrades for 1.2.2
Summary: Recipe security upgrades for 1.2.2
Status: RESOLVED INVALID
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 1.2.1
Hardware: x86 Multiple
: Medium normal
Target Milestone: 1.2.2
Assignee: Scott Garman
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2012-07-03 17:06 UTC by Scott Garman
Modified: 2012-07-05 15:15 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Scott Garman 2012-07-03 17:06:54 UTC
It's too late to get these into 1.2.1, but these recipes will need to get upgraded for 1.2.2:

openssl:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333

libpng:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3048

xinetd:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0862

libxml2:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1025
Comment 1 Jessica 2012-07-05 14:43:08 UTC
Please file 4 separate bugs since each pacakge is owned by different people
Comment 2 Scott Garman 2012-07-05 15:15:18 UTC
I've now filed separate bugs for these, so I'm closing this one.

openssl - bug #2701

xinetd - bug #2702

libxml2 - bug #2703

I was mistaken about libpng, the version we ship is actually safe.