From 48d2305f488b9613707ef830beca9d1760a394e5 Mon Sep 17 00:00:00 2001 From: Gyorgy Sarvari Date: Sun, 30 Nov 2025 20:44:12 +0100 Subject: [PATCH] fontforge: ignore CVE-2019-15785 Details: https://nvd.nist.gov/vuln/detail/CVE-2019-15785 The vulnerability is not present in the currently used version, so ignore it. Current version: 20190801 First vulnerable version: 20190813 Signed-off-by: Gyorgy Sarvari --- meta-oe/recipes-graphics/fontforge/fontforge_20190801.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-oe/recipes-graphics/fontforge/fontforge_20190801.bb b/meta-oe/recipes-graphics/fontforge/fontforge_20190801.bb index cb5f4d5ea1..84644f2560 100644 --- a/meta-oe/recipes-graphics/fontforge/fontforge_20190801.bb +++ b/meta-oe/recipes-graphics/fontforge/fontforge_20190801.bb @@ -43,5 +43,8 @@ FILES:${PN} += " \ FILES:${PN}-python = "${PYTHON_SITEPACKAGES_DIR} ${datadir}/${BPN}/python" RDEPENDS:${PN}-python = "python3" +# The vulnerability was introduced after the used revision. +CVE_CHECK_IGNORE += "CVE-2019-15785" + # for e.g kde's oxygen-fonts BBCLASSEXTEND = "native"