Skip to content
Commit 06b72a91 authored by Mikko Rapeli's avatar Mikko Rapeli Committed by Richard Purdie
Browse files

zip: whitelist CVE-2018-13410 and CVE-2018-13684

https://nvd.nist.gov/vuln/detail/CVE-2018-13410 is disputed and
also Debian considers it not a vulnerability:

https://security-tracker.debian.org/tracker/CVE-2018-13410

http://seclists.org/fulldisclosure/2018/Jul/24
"Negligible security impact, would involve that a untrusted party controls the -TT value."

https://nvd.nist.gov/vuln/detail/CVE-2018-13684 is not for zip, also Debian concludes this:

https://security-tracker.debian.org/tracker/CVE-2018-13684



"NOT-FOR-US: smart contract implementation for ZIP"

Signed-off-by: default avatarMikko Rapeli <mikko.rapeli@bmw.de>
Signed-off-by: default avatarRichard Purdie <richard.purdie@linuxfoundation.org>
parent ef153ad3
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment