Skip to content
This repository has been archived by the owner on Jan 6, 2023. It is now read-only.

Backport CVE fixes for Flex and Gnutls. #46

Merged
merged 2 commits into from
Oct 20, 2016
Merged

Conversation

ipuustin
Copy link
Contributor

Fixes two Ostro OS vulnerabilities: ostroproject/ostro-os#194 and ostroproject/ostro-os#196 (CVE-2016-6354 and CVE-2016-7444).

Fix a critical vulnerability in Flex. The patch is backported from
oe-core mailing list
(http://marc.info/?l=openembedded-core&m=147608835319240).

CVE: CVE-2016-6354
Upstream-status: Backport [westes/flex@a5cbe92]

Signed-off-by: Ismo Puustinen <[email protected]>
Fix a vulnerability in gnutls. The fix is backported from oe-core
mailing list (http://marc.info/?l=openembedded-core&m=147608834019235).

CVE: CVE-2016-7444
Upstream-status: Backport [https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9]

Signed-off-by: Ismo Puustinen <[email protected]>
@okartau
Copy link
Contributor

okartau commented Oct 12, 2016

strange.. CI build was ok, test failed, but status here was set to "OK"

@okartau
Copy link
Contributor

okartau commented Oct 12, 2016

Seems we discovered new issue via this, which I wrote down as:
#47

pohly added a commit to pohly/ostro-os-xt that referenced this pull request Oct 13, 2016
This manual merge includes PRs ostroproject#41, ostroproject#44, ostroproject#45, ostroproject#46, ostroproject#48. Doing that in
one step is faster than merging individually.

Signed-off-by: Patrick Ohly <[email protected]>
mythi added a commit to mythi/ostro-os-xt-1 that referenced this pull request Oct 19, 2016
This manual merge includes PRs ostroproject#21, ostroproject#36, ostroproject#44, ostroproject#45, ostroproject#46, ostroproject#48, ostroproject#49,
and ostroproject#52. Doing that in one step is faster than merging individually.

Signed-off-by: Mikko Ylinen <[email protected]>
mythi added a commit to mythi/ostro-os-xt-1 that referenced this pull request Oct 19, 2016
This manual merge includes PRs ostroproject#21, ostroproject#36, ostroproject#44, ostroproject#45, ostroproject#46, ostroproject#49,
and ostroproject#52. Doing that in one step is faster than merging individually.

Signed-off-by: Mikko Ylinen <[email protected]>
mythi added a commit to mythi/ostro-os-xt-1 that referenced this pull request Oct 20, 2016
This manual merge includes PRs ostroproject#21, ostroproject#36, ostroproject#44, ostroproject#45, ostroproject#46, ostroproject#49,
and ostroproject#52. Doing that in one step is faster than merging individually.

Signed-off-by: Mikko Ylinen <[email protected]>
mythi added a commit to mythi/ostro-os-xt-1 that referenced this pull request Oct 20, 2016
This manual merge includes PRs ostroproject#21, ostroproject#36, ostroproject#44, ostroproject#45, ostroproject#46, ostroproject#48, ostroproject#49, ostroproject#52
and ostroproject#56. Doing that in one step is faster than merging individually.

Signed-off-by: Mikko Ylinen <[email protected]>
@mythi mythi merged commit a4882f7 into ostroproject:master Oct 20, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants