diff options
| author | Gyorgy Sarvari <skandigraun@gmail.com> | 2025-11-28 21:18:34 +0100 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2025-11-30 15:13:58 +0100 |
| commit | 4cf5f8cc31820e486a6a7821d9fdbf55dea7df06 (patch) | |
| tree | e28ae7e3bcd24cd32396731c56f7afe576474d2d /meta-multimedia | |
| parent | f81db4757e09dd812afba89385f0b60d0bc1612d (diff) | |
| download | meta-openembedded-4cf5f8cc31820e486a6a7821d9fdbf55dea7df06.tar.gz | |
libao: ignore CVE-2017-11548
Both Suse[1] and Debian[2] disputes that this is a vulnerability in libao.
Based on their investigation while an issue exists, it is not in libao, however
higher in the audio-toolchain, most likely in libmad or mpg321. There seem to
be nothing to be fixed about this in libao - ignore this CVE due to this.
[1]: https://bugzilla.suse.com/show_bug.cgi?id=1081767
[2]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870608
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit a993eb8b93f16e3a16c9a1ab2eb0939cb2331593)
Reworked for Kirkstone (CVE_STATUS -> CVE_CHECK_IGNORE)
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-multimedia')
| -rw-r--r-- | meta-multimedia/recipes-multimedia/libao/libao_1.2.0.bb | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/meta-multimedia/recipes-multimedia/libao/libao_1.2.0.bb b/meta-multimedia/recipes-multimedia/libao/libao_1.2.0.bb index b30f398e87..0a424d622a 100644 --- a/meta-multimedia/recipes-multimedia/libao/libao_1.2.0.bb +++ b/meta-multimedia/recipes-multimedia/libao/libao_1.2.0.bb | |||
| @@ -31,3 +31,6 @@ PACKAGECONFIG ?= "${@bb.utils.filter('DISTRO_FEATURES', 'alsa pulseaudio', d)}" | |||
| 31 | PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib" | 31 | PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib" |
| 32 | PACKAGECONFIG[pulseaudio] = "--enable-pulse,--disable-pulse,pulseaudio" | 32 | PACKAGECONFIG[pulseaudio] = "--enable-pulse,--disable-pulse,pulseaudio" |
| 33 | FILES:${BPN}-ckport = "${libdir}/ckport" | 33 | FILES:${BPN}-ckport = "${libdir}/ckport" |
| 34 | |||
| 35 | # disputed: the referenced vulnerability is not in libao | ||
| 36 | CVE_CHECK_IGNORE += "CVE-2017-11548" | ||
