kumquat-buildroot/package/flex
Matt Weber 120d1241d8 package/flex: ignore CVE-2019-6293
https://security-tracker.debian.org/tracker/CVE-2019-6293

https://github.com/NixOS/nixpkgs/issues/55386#issuecomment-683792976
 "But this bug does not cause stack overflows in the generated code.
 The function and file referred to in the bug (mark_beginning_as_normal
 in nfa.c) are part of the flex code generator, not part of the
 generated code. If flex crashes before generating any code, that
 can hardly be a vulnerability. If flex does not crash, the generated
 code is fine (or perhaps subject to other unreported bugs, who knows,
 but the NFA has been generated correctly)."

Upstream has chosen to not provide a fix
 https://github.com/westes/flex/issues/414

Signed-off-by: Matthew Weber <matthew.weber@rockwellcollins.com>
[yann.morin.1998@free.fr: use actual upstream URL]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2021-04-24 11:25:33 +02:00
..
0001-build-AC_USE_SYSTEM_EXTENSIONS-in-configure.ac.patch
0002-build-make-it-possible-to-disable-the-build-of-the-f.patch
0003-build-make-it-possible-to-disable-the-build-of-the-d.patch
Config.in
flex.hash
flex.mk package/flex: ignore CVE-2019-6293 2021-04-24 11:25:33 +02:00