Files
meta-openembedded/meta-networking/recipes-connectivity
Gyorgy Sarvari d27a3be1f6 ez-ipupdate: patch CVE-2003-0887
Details: https://nvd.nist.gov/vuln/detail/CVE-2003-0887

The vulnerability is about the default (example) configurations,
which place cache files into the /tmp folder, that is world-writeable.
The recommendation would be to place them to a more secure folder.

The recipe however does not install these example configurations,
and as such it is not vulnerable either.

Just to make sure, patch these folders to a non-tmp folder
(and also install that folder, empty).

Some more discussion about the vulnerability:
https://bugzilla.suse.com/show_bug.cgi?id=48161

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit dd81ffdb68)
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
2026-02-13 17:03:50 +01:00
..
2026-01-08 22:03:02 +01:00
2022-02-04 09:27:57 -08:00
2025-12-16 08:39:06 +01:00
2021-08-03 10:21:25 -07:00
2025-09-26 15:13:03 +02:00
2025-04-20 13:43:06 -04:00
2021-08-03 10:21:25 -07:00
2024-02-07 18:41:41 -05:00