diff options
| author | Peter Marko <peter.marko@siemens.com> | 2026-01-01 10:16:28 +0100 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-01-08 22:03:03 +0100 |
| commit | 6b7a0197f94098316775625839bb334572ae5f63 (patch) | |
| tree | 40b7154cfe2e01399d4d5ce7fc53ab04e26e30cf /meta-networking | |
| parent | 71adc2f371177c9de19d35fbd6c2472bc11f49bf (diff) | |
| download | meta-openembedded-6b7a0197f94098316775625839bb334572ae5f63.tar.gz | |
proftpd: set status of CVE-2001-0027
This ancient CVE [1] is unversioned ("*") in NVD DB.
"mod_sqlpw module in ProFTPD does not reset a cached password..."
Looking at history and changelog, the module was removed [2] around
the time when this CVE was published, likely as reaction to this CVE.
"mod_sqlpw.c, mod_mysql.c and mod_pgsql.c have been REMOVED from the
distribution. They are currently unmaintained and have numerous bugs."
Note: It was later re-introduced as mod_sql when it got fixed under
new maintainer.
[1] https://nvd.nist.gov/vuln/detail/CVE-2001-0027
[2] https://github.com/proftpd/proftpd/blob/v1.3.8b/NEWS#L3362
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 03a1b56bc7ce88a3b0ad6790606b0498899cc1e3)
Adapted to Kirkstone (CVE_STATUS -> CVE_CHECK_IGNORE)
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-networking')
| -rw-r--r-- | meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb b/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb index 345c714a52..b8f2b50f79 100644 --- a/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb +++ b/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb | |||
| @@ -25,6 +25,9 @@ S = "${WORKDIR}/git" | |||
| 25 | 25 | ||
| 26 | inherit autotools-brokensep useradd update-rc.d systemd multilib_script | 26 | inherit autotools-brokensep useradd update-rc.d systemd multilib_script |
| 27 | 27 | ||
| 28 | # fixed-version: version 1.2.0rc3 removed affected module | ||
| 29 | CVE_CHECK_IGNORE += "CVE-2001-0027" | ||
| 30 | |||
| 28 | PACKAGECONFIG ??= "shadow \ | 31 | PACKAGECONFIG ??= "shadow \ |
| 29 | ${@bb.utils.filter('DISTRO_FEATURES', 'ipv6 pam', d)} \ | 32 | ${@bb.utils.filter('DISTRO_FEATURES', 'ipv6 pam', d)} \ |
| 30 | static \ | 33 | static \ |
