All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: [Buildroot] [autobuild.buildroot.net] Your daily results for 2021-08-15
@ 2021-08-17 10:35 Peter Korsgaard
  2021-08-17 10:56 ` Thomas Petazzoni
  0 siblings, 1 reply; 6+ messages in thread
From: Peter Korsgaard @ 2021-08-17 10:35 UTC (permalink / raw)
  To: Thomas Petazzoni, buildroot

>>>>> "Thomas" == Thomas Petazzoni <thomas.petazzoni@bootlin.com> writes:

Hi,

 > Packages having CVEs
 > ====================

 > This is the list of packages for which a known CVE is affecting them,
 > which means a security vulnerability exists for those packages.

 > CVEs for the 'master' branch
 > ----------------------------

 >              name              |       CVE        |                             link                            
 > -------------------------------+------------------+--------------------------------------------------------------
 >                      mosquitto | CVE-2021-34432   | https://security-tracker.debian.org/tracker/CVE-2021-34432  


 > CVEs for the '2021.02.x' branch
 > -------------------------------

 >              name              |       CVE        |                             link                            
 > -------------------------------+------------------+--------------------------------------------------------------
 >                      mosquitto | CVE-2021-34432   | https://security-tracker.debian.org/tracker/CVE-2021-34432  


 > CVEs for the '2021.05.x' branch
 > -------------------------------

 >              name              |       CVE        |                             link                            
 > -------------------------------+------------------+--------------------------------------------------------------
 >                      mosquitto | CVE-2021-34432   | https://security-tracker.debian.org/tracker/CVE-2021-34432  


 > CVEs for the 'next' branch
 > --------------------------

 >              name              |       CVE        |                             link                            
 > -------------------------------+------------------+--------------------------------------------------------------
 >                      mosquitto | CVE-2021-34432   | https://security-tracker.debian.org/tracker/CVE-2021-34432  

Hmm, looks like we have a bug in the version comparison logic. We have
2.0.11 and the CPE data states <= 2.0.7:

https://nvd.nist.gov/vuln/detail/CVE-2021-34432

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@busybox.net
http://lists.busybox.net/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2021-08-18 10:18 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-08-17 10:35 [Buildroot] [autobuild.buildroot.net] Your daily results for 2021-08-15 Peter Korsgaard
2021-08-17 10:56 ` Thomas Petazzoni
2021-08-17 11:10   ` Peter Korsgaard
2021-08-17 11:12     ` Thomas Petazzoni
2021-08-17 15:42       ` Peter Korsgaard
2021-08-18 10:17         ` Thomas Petazzoni

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.