Re: [oe-core][PATCH 1/1] perl: Fix CVE-2023-31486

2023-07-17 Thread Soumya via lists.openembedded.org
...@sakoman.com ; G Pillai, Hari Subject: Re: [oe-core][PATCH 1/1] perl: Fix CVE-2023-31486 CAUTION: This email comes from a non Wind River email account! Do not click links or open attachments unless you recognize the sender and know the content is safe. Hello, you pressed y instead of enter when git

Re: [oe-core][PATCH 1/1] perl: Fix CVE-2023-31486

2023-07-17 Thread Alexandre Belloni via lists.openembedded.org
Hello, you pressed y instead of enter when git asked you what wharset to use, so the patch doesn't apply. Can you resend? On 14/07/2023 03:25:10+, Soumya via lists.openembedded.org wrote: > HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available > standalone on CPAN, has an in

[oe-core][PATCH 1/1] perl: Fix CVE-2023-31486

2023-07-13 Thread Soumya via lists.openembedded.org
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. References: https://nvd.nist.gov/vuln/detail/CVE-2023-31486 Upstream patches: https://github.com/chansen/p5-http-tin