<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meta-mlinux.git/recipes-crypto, branch 6.3.1</title>
<subtitle>mLinux Distribution Layer</subtitle>
<link rel='alternate' type='text/html' href='https://git.multitech.net/cgit/meta-mlinux.git/'/>
<entry>
<title>Switch to cryptsetup 2.3.7</title>
<updated>2023-01-25T12:02:10+00:00</updated>
<author>
<name>Mykyta Dorokhin</name>
<email>mykyta.dorokhin@globallogic.com</email>
</author>
<published>2023-01-25T12:01:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.multitech.net/cgit/meta-mlinux.git/commit/?id=2552c0524cb1772bef1604b475628cd1dc481b96'/>
<id>2552c0524cb1772bef1604b475628cd1dc481b96</id>
<content type='text'>
Fix mtcpmhs build
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fix mtcpmhs build
</pre>
</div>
</content>
</entry>
<entry>
<title>CVE Packages Update</title>
<updated>2023-01-24T10:41:29+00:00</updated>
<author>
<name>Andrii Davydenko</name>
<email>andrii.davydenko@globallogic.com</email>
</author>
<published>2022-12-14T10:08:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.multitech.net/cgit/meta-mlinux.git/commit/?id=2eaa3fd064097eb221b56d5df0e7136ba705a0cd'/>
<id>2eaa3fd064097eb221b56d5df0e7136ba705a0cd</id>
<content type='text'>
Move libfastjson to the rsyslog directory

rsyslog 8.2002.0 -&gt; 8.2206.0

add ntp4.2.8 recipe with fixed CVEs

update cryptsetup to 2.4.3

fix libxml2 CVE-2016-3709

curl 7.75.0 -&gt; 7.86.0

strongswan 5.8.4 -&gt; 5.9.8

libmodbus 3.1.6 -&gt; 3.1.7

libesmtp 1.0.6 -&gt; 1.1.0

cifs-utils 6.1 -&gt; 7.0

update libtirpc to version 1.3.3

update rsync to version 3.2.5

Add zlib 1.2.13

upgrade gnutls to 3.7.8

upgrade openssh to 8.9p1

Add cmake 3.24.2 and cmake-native 3.24.2 to avoid loop dependecies building expat

Add expat 2.5.0 to fix CVE-2022-40674 and CVE-2022-43680

openvpn 2.4.9 -&gt; 2.4.12

hostapd 2.9 -&gt; 2.10

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Openssh 8.9p1 no longer needed, because all necessary CVE fixes, backports and whitelists are present for current Openssh 8.4p1. There are no new CVE's in report.

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Backported CVE patches for python3 component. Need to remove after upgrading Yocto to version more than 3.1.21.

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Backported CVE patch for sudo component.
Added 2 CVE's to whitelist for OpenVPN component.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Move libfastjson to the rsyslog directory

rsyslog 8.2002.0 -&gt; 8.2206.0

add ntp4.2.8 recipe with fixed CVEs

update cryptsetup to 2.4.3

fix libxml2 CVE-2016-3709

curl 7.75.0 -&gt; 7.86.0

strongswan 5.8.4 -&gt; 5.9.8

libmodbus 3.1.6 -&gt; 3.1.7

libesmtp 1.0.6 -&gt; 1.1.0

cifs-utils 6.1 -&gt; 7.0

update libtirpc to version 1.3.3

update rsync to version 3.2.5

Add zlib 1.2.13

upgrade gnutls to 3.7.8

upgrade openssh to 8.9p1

Add cmake 3.24.2 and cmake-native 3.24.2 to avoid loop dependecies building expat

Add expat 2.5.0 to fix CVE-2022-40674 and CVE-2022-43680

openvpn 2.4.9 -&gt; 2.4.12

hostapd 2.9 -&gt; 2.10

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Openssh 8.9p1 no longer needed, because all necessary CVE fixes, backports and whitelists are present for current Openssh 8.4p1. There are no new CVE's in report.

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Backported CVE patches for python3 component. Need to remove after upgrading Yocto to version more than 3.1.21.

[GP-1837] mPower R.6.3.X (Fall'22): CVE Upgrade (after 2022-12-28)
Backported CVE patch for sudo component.
Added 2 CVE's to whitelist for OpenVPN component.
</pre>
</div>
</content>
</entry>
</feed>
