[OE-core] bash: Fix CVE-2019-18276

Yu, Mingli Mingli.Yu at windriver.com
Wed Mar 4 01:16:42 UTC 2020


Got it, thanks Anuj!

Thanks,
Mingli
________________________________________
From: openembedded-core-bounces at lists.openembedded.org [openembedded-core-bounces at lists.openembedded.org] on behalf of Mittal, Anuj [anuj.mittal at intel.com]
Sent: Wednesday, March 04, 2020 7:49 AM
To: openembedded-core at lists.openembedded.org
Subject: Re: [OE-core] bash: Fix CVE-2019-18276

On Tue, 2020-03-03 at 03:11 +0000, Yu, Mingli wrote:
> Hi Anuj,
>
> I agree the Backport status is not accurate as the patch doesn't go
> to master branch, but why do you say the patch is irrelevant to the
> CVE-2019-18276, could you help to provide more info?

I didn't say that the patch was irrelevant to the CVE. I had said that
not all the changes were relevant. I believe the glob changes in the
patch were irrelevant. Those changes also introduced a failure in bash
ptests.

Thanks,

Anuj
--
_______________________________________________
Openembedded-core mailing list
Openembedded-core at lists.openembedded.org
http://lists.openembedded.org/mailman/listinfo/openembedded-core


More information about the Openembedded-core mailing list