From c43e538c0f1e961ac1d307ca22e925b16686cce4 Mon Sep 17 00:00:00 2001 From: Daniel Lang Date: Wed, 20 Sep 2023 06:31:12 +0200 Subject: [PATCH] package/bind: drop CVE-2017-3139 from IGNORE_CVES As of 2021-05-14 CVE-2017-3139 is no longer listed as affecting bind, only RHEL. Signed-off-by: Daniel Lang Signed-off-by: Yann E. MORIN (cherry picked from commit 8bf82aab0c0b7a1d329a02395e0353bb9c2eae67) Signed-off-by: Peter Korsgaard --- package/bind/bind.mk | 2 -- 1 file changed, 2 deletions(-) diff --git a/package/bind/bind.mk b/package/bind/bind.mk index b934ab3190..618b5b9278 100644 --- a/package/bind/bind.mk +++ b/package/bind/bind.mk @@ -14,8 +14,6 @@ BIND_LICENSE = MPL-2.0 BIND_LICENSE_FILES = COPYRIGHT BIND_CPE_ID_VENDOR = isc BIND_SELINUX_MODULES = bind -# Only applies to RHEL6.x with DNSSEC validation on -BIND_IGNORE_CVES = CVE-2017-3139 # Library CVE and not used by bind but used by ISC DHCP BIND_IGNORE_CVES += CVE-2019-6470 BIND_TARGET_SERVER_SBIN = arpaname ddns-confgen dnssec-checkds dnssec-coverage