package/rsyslog: ignore CVE-2015-3243
authorMatt Weber <matthew.weber@rockwellcollins.com>
Wed, 21 Apr 2021 20:42:34 +0000 (15:42 -0500)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 24 Apr 2021 09:28:05 +0000 (11:28 +0200)
commitfb4402b51693e8d191bb568622ed9cf9315493fd
tree492e54b6d35239613a79a6407a615e7b034d318e
parent675769791bd43de18b6bbeec2b4b48772a541a7a
package/rsyslog: ignore CVE-2015-3243

https://security-tracker.debian.org/tracker/CVE-2015-3243
 "Rsyslog uses weak permissions for generating log files."

Ignoring this CVE for Buildroot as normally there are not local
users and a build could customize the rsyslog.conf to be more
restrictive ($FileCreateMode 0640).

Example fix from Alpino Linux
 https://github.com/libTorrentUser/alpino-linux-aports/commit/3cb5210cdac46fb8805d4028df16f5889f393a09

Signed-off-by: Matthew Weber <matthew.weber@rockwellcollins.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/rsyslog/rsyslog.mk