From 3a819d34c695fbca427f273936a39952b5b53f1c Mon Sep 17 00:00:00 2001 From: Ninette Adhikari Date: Fri, 14 Jun 2024 07:19:11 -0400 Subject: [PATCH] smarty: Update status for CVE-2020-10375 The recipe used in the meta-openembedded is a different package compared to the one which has the CVE issue. Package used in meta-embedded: https://www.smarty.net/ Package with CVE issue is from newmediacompany: https://www.smarty-online.de No action required. Signed-off-by: Ninette Adhikari Signed-off-by: Khem Raj --- meta-oe/recipes-support/smarty/smarty_4.4.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-support/smarty/smarty_4.4.1.bb b/meta-oe/recipes-support/smarty/smarty_4.4.1.bb index 1caa4cd1bb..e0979bb5aa 100644 --- a/meta-oe/recipes-support/smarty/smarty_4.4.1.bb +++ b/meta-oe/recipes-support/smarty/smarty_4.4.1.bb @@ -24,3 +24,5 @@ do_install() { install -m 0644 ${S}/libs/sysplugins/*.php ${D}${datadir}/php/smarty3/libs/sysplugins/ } FILES:${PN} = "${datadir}/php/smarty3/" + +CVE_STATUS[CVE-2020-10375] = "cpe-incorrect: The recipe used in the meta-openembedded is a different smarty package compared to the one which has the CVE issue."