diff options
| author | Peter Marko <peter.marko@siemens.com> | 2023-03-14 20:49:28 +0100 |
|---|---|---|
| committer | Khem Raj <raj.khem@gmail.com> | 2023-04-19 09:39:15 -0700 |
| commit | 648912f72d3d85ef43ba5114953794faa1572bdf (patch) | |
| tree | a259da8f1486f7a496ad5b9584428d20e8d72730 | |
| parent | daa0c135a8919e7b7f427ce71528faec6ef7edd3 (diff) | |
| download | meta-openembedded-648912f72d3d85ef43ba5114953794faa1572bdf.tar.gz | |
ntp: whitelist CVE-2019-11331
Links from https://nvd.nist.gov/vuln/detail/CVE-2019-11331 lead to
conclusion that this is how icurrent ntp protocol is designed.
New RFC is propsed for future but it will not be compatible with current
one.
See https://support.f5.com/csp/article/K09940637
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
| -rw-r--r-- | meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb b/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb index 3ce2d77df7..5d2f05e925 100644 --- a/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb +++ b/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb | |||
| @@ -27,6 +27,7 @@ SRC_URI = "http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-4.2/ntp-${PV}.tar.g | |||
| 27 | SRC_URI[sha256sum] = "f65840deab68614d5d7ceb2d0bb9304ff70dcdedd09abb79754a87536b849c19" | 27 | SRC_URI[sha256sum] = "f65840deab68614d5d7ceb2d0bb9304ff70dcdedd09abb79754a87536b849c19" |
| 28 | 28 | ||
| 29 | # CVE-2016-9312 is only for windows. | 29 | # CVE-2016-9312 is only for windows. |
| 30 | # CVE-2019-11331 is inherent to RFC 5905 and cannot be fixed without breaking compatibility | ||
| 30 | # The other CVEs are not correctly identified because cve-check | 31 | # The other CVEs are not correctly identified because cve-check |
| 31 | # is not able to check the version correctly (it only checks for 4.2.8 omitting p15 that makes the difference) | 32 | # is not able to check the version correctly (it only checks for 4.2.8 omitting p15 that makes the difference) |
| 32 | CVE_CHECK_IGNORE += "\ | 33 | CVE_CHECK_IGNORE += "\ |
| @@ -50,6 +51,7 @@ CVE_CHECK_IGNORE += "\ | |||
| 50 | CVE-2016-7433 \ | 51 | CVE-2016-7433 \ |
| 51 | CVE-2016-9310 \ | 52 | CVE-2016-9310 \ |
| 52 | CVE-2016-9311 \ | 53 | CVE-2016-9311 \ |
| 54 | CVE-2019-11331 \ | ||
| 53 | " | 55 | " |
| 54 | 56 | ||
| 55 | 57 | ||
