package/erlang: ignore Windows specific CVE-2021-29221
authorPeter Korsgaard <peter@korsgaard.com>
Sat, 18 Sep 2021 16:59:46 +0000 (18:59 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 18 Sep 2021 17:42:50 +0000 (19:42 +0200)
commite7c2eaf92949ea20bb0882c088f76b7becb95a64
tree928fb6fdf3105a2f2361c5555618ba5e36dd3cee
parent31c94080d26ed97561f1418198a2716caab0cdb3
package/erlang: ignore Windows specific CVE-2021-29221

CVE-2021-29221 is a Windows specific issue:

A local privilege escalation vulnerability was discovered in Erlang/OTP
prior to version 23.2.3.  By adding files to an existing installation's
directory, a local attacker could hijack accounts of other users running
Erlang programs or possibly coerce a service running with "erlsrv.exe" to
execute arbitrary code as Local System.  This can occur only under specific
conditions on Windows with unsafe filesystem permissions.

So ignore it.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/erlang/erlang.mk