From 5b84ee352f2ad365eeb52aebb092752c58c5b194 Mon Sep 17 00:00:00 2001 From: Daniel Lang Date: Thu, 21 Sep 2023 05:58:27 +0200 Subject: [PATCH] package/fail2ban: drop CVE-2021-32749 from IGNORE_CVES CVE-2021-32749 affects fail2ban <= 0.9.7, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2. The mentioned patch was removed in 76853089 when bumping to 1.0.1. Signed-off-by: Daniel Lang Signed-off-by: Thomas Petazzoni (cherry picked from commit a01a6b8dc840eb99528d3c876d18e1f8952d2a58) Signed-off-by: Peter Korsgaard --- package/fail2ban/fail2ban.mk | 3 --- 1 file changed, 3 deletions(-) diff --git a/package/fail2ban/fail2ban.mk b/package/fail2ban/fail2ban.mk index 7ad22d02d1..34f2341d33 100644 --- a/package/fail2ban/fail2ban.mk +++ b/package/fail2ban/fail2ban.mk @@ -12,9 +12,6 @@ FAIL2BAN_CPE_ID_VENDOR = fail2ban FAIL2BAN_SELINUX_MODULES = fail2ban FAIL2BAN_SETUP_TYPE = distutils -# 0001-fixed-possible-RCE-vulnerability-unset-escape-variable.patch -FAIL2BAN_IGNORE_CVES += CVE-2021-32749 - define FAIL2BAN_PYTHON_2TO3 $(HOST_DIR)/bin/2to3 --write --nobackups --no-diffs $(@D)/bin/* $(@D)/fail2ban endef