diff options
author | Yi Zhao <yi.zhao@windriver.com> | 2021-09-26 11:16:42 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2021-09-26 12:05:03 +0100 |
commit | eafac9940adb69f085e1448516ab59976a16489b (patch) | |
tree | 9643d2cc9f81f6b90321afbd32e42a8a8664c4c4 /meta/recipes-multimedia | |
parent | 06dcace68b021b020f14327c35358d58ecc698fa (diff) | |
download | poky-eafac9940adb69f085e1448516ab59976a16489b.tar.gz |
inetutils: fix CVE-2021-40491
CVE-2021-40491:
The ftp client in GNU Inetutils before 2.2 does not validate addresses
returned by PASV/LSPV responses to make sure they match the server
address. This is similar to CVE-2020-8284 for curl.
References:
https://nvd.nist.gov/vuln/detail/CVE-2021-40491
Patch from:
https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50dd
(From OE-Core rev: 1b857807f1cf8fee3175f8479a0c7cb1850bd9a9)
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-multimedia')
0 files changed, 0 insertions, 0 deletions