From b25f1cb47c55dab9de706d61809936839cfe8f5f Mon Sep 17 00:00:00 2001 From: Daniel Lang <dalang@gmx.at> Date: Wed, 6 Sep 2023 21:49:51 +0200 Subject: [PATCH] package/libiec61850: ignore CVE-2023-27772 Segmentation fault in example code can be exploited. BUILD_EXAMPLES is disabled for all cmake projects. See https://github.com/mz-automation/libiec61850/issues/442 Signed-off-by: Daniel Lang <dalang@gmx.at> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> --- package/libiec61850/libiec61850.mk | 3 +++ 1 file changed, 3 insertions(+) diff --git a/package/libiec61850/libiec61850.mk b/package/libiec61850/libiec61850.mk index 9bd55cb76a..4b61e40c6d 100644 --- a/package/libiec61850/libiec61850.mk +++ b/package/libiec61850/libiec61850.mk @@ -11,5 +11,8 @@ LIBIEC61850_LICENSE = GPL-3.0+ LIBIEC61850_LICENSE_FILES = COPYING LIBIEC61850_CPE_ID_VENDOR = mz-automation LIBIEC61850_CONF_OPTS = -DBUILD_PYTHON_BINDINGS=OFF +# Examples aren't build +# https://github.com/mz-automation/libiec61850/issues/442 +LIBIEC61850_IGNORE_CVES += CVE-2023-27772 $(eval $(cmake-package))