kumquat-buildroot/package/exim
Peter Korsgaard 43d5ff7ee4 package/exim: mark CVE-2022-3620 as ignored
CVE-2022-3620: A vulnerability was found in Exim and classified as
problematic.  This issue affects the function dmarc_dns_lookup of the file
dmarc.c of the component DMARC Handler.  The manipulation leads to use after
free.  The attack may be initiated remotely.  The name of the patch is
12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445.  It is recommended to apply a
patch to fix this issue.  The associated identifier of this vulnerability is
VDB-211919.

This vulnerability is in the DMARC handling, which is only used if
libopendmarc is available AND SUPPORT_DMARC is set to yes, neither of which
is true for Buildroot, so ignore the CVE.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2022-12-03 15:31:29 +01:00
..
0001-Build-buildconfig-for-the-host.patch
0002-Don-t-make-backup-copies-of-installed-files.patch
0003-Skip-version-check-and-symlink-installation.patch
0004-exim_lock-fix-lstat-related-build-errors.patch
0005-sieve-fix-build-errors.patch
0006-Fix-regex-n-use-after-free.-Bug-2915.patch
0007-Fix-non-WITH_CONTENT_SCAN-build.patch
0008-Fix-non-WITH_CONTENT_SCAN-build-2.patch
0009-Fix-non-WITH_CONTENT_SCAN-build-3.patch
Config.in
exim.hash
exim.mk package/exim: mark CVE-2022-3620 as ignored 2022-12-03 15:31:29 +01:00
exim.service
S86exim