[prev in list] [next in list] [prev in thread] [next in thread] 

List:       buildroot
Subject:    Re: [Buildroot] [PATCH 1/1] package/php: ignore various CVEs
From:       Bernd Kuhls <bernd.kuhls () t-online ! de>
Date:       2022-07-31 12:29:26
Message-ID: pan$451db$f0fedacb$1d38fc5e$2b25cd7b () ID-313208 ! user ! individual ! net
[Download RAW message or body]

Am Sun, 31 Jul 2022 15:02:57 +0300 schrieb Baruch Siach via buildroot:

> I share your desire to make the weekly list more useful. My question is
> why current version check method does not filter out these CVEs
> automatically?

Hi Baruch,

because many CVS entries I added to the ignore lists do not contain any 
version number in the NVD database, for example:

https://nvd.nist.gov/vuln/detail/CVE-1999-0236

cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*

Regards, Bernd

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic