[Bf-blender-cvs] [49b7a7efca1] blender-v3.3-release: Build: ignore more CVEs from tiff command line tools that we don't use

Brecht Van Lommel noreply at git.blender.org
Thu Nov 3 15:04:29 CET 2022


Commit: 49b7a7efca1b1ea5bc5be4068eb2b6e2cf0a9258
Author: Brecht Van Lommel
Date:   Mon Oct 31 20:05:11 2022 +0100
Branches: blender-v3.3-release
https://developer.blender.org/rB49b7a7efca1b1ea5bc5be4068eb2b6e2cf0a9258

Build: ignore more CVEs from tiff command line tools that we don't use

===================================================================

M	build_files/build_environment/cmake/cve_check.csv.in

===================================================================

diff --git a/build_files/build_environment/cmake/cve_check.csv.in b/build_files/build_environment/cmake/cve_check.csv.in
index 734a24f8c77..946dda5ab17 100644
--- a/build_files/build_environment/cmake/cve_check.csv.in
+++ b/build_files/build_environment/cmake/cve_check.csv.in
@@ -17,6 +17,12 @@ vendor,product,version,cve_number,remarks,comment
 @TIFF_ID@,CVE-2022-2521,Ignored,issue in tiff command line tool not used by blender
 @TIFF_ID@,CVE-2022-2953,Ignored,issue in tiff command line tool not used by blender
 @TIFF_ID@,CVE-2022-34526,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3570,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3597,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3598,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3599,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3626,Ignored,issue in tiff command line tool not used by blender
+ at TIFF_ID@,CVE-2022-3627,Ignored,issue in tiff command line tool not used by blender
 @XML2_ID@,CVE-2016-3709,Ignored,not affecting blender and not considered a security issue upstream
 @GMP_ID@,CVE-2021-43618,Mitigated,patched using upstream commit 561a9c25298e
 @SQLITE_ID@,CVE-2022-35737,Ignored,only affects SQLITE_ENABLE_STAT4 compile option not used by blender or python



More information about the Bf-blender-cvs mailing list