{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2026-01-24T12:25:07Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/document/package-tzcode","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/glibc/package-tzcode/glibc/UNIHASH/document/package-tzcode"}],"name":"package-tzcode","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode","creationInfo":"_:CreationInfo1","description":"tzcode, timezone zoneinfo utils -- zic, zdump, tzselect","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/package/tzcode"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:glibc:2.42:*:*:*:*:*:*:*"}],"name":"tzcode","summary":"GLIBC (GNU C Library)","software_primaryPurpose":"install","software_homePage":"http://www.gnu.org/software/libc/libc.html","software_packageVersion":"2.42+git"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/package/tzcode/file/1"}],"name":"usr/bin/tzselect","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"87c5e4073e0212311a62fe4b7c940b2c272e5040e1af3179798ac8419a989102"}]},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/2","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/package/tzcode/file/2"}],"name":"usr/bin/zdump","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"5ad1039aef6ede556ca819fa4e98a662ad4680d18f86963ef556caf4eaadda44"}]},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/3","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/package/tzcode/file/3"}],"name":"usr/sbin/zic","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"6e713b0dd5229338b579421bc2e82aa271499141aeeb4aad65dfb8fbada41c2e"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/relationship/11bddb282d4bfae33ad07ca1b803cafa","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/relationship/11bddb282d4bfae33ad07ca1b803cafa"}],"from":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/license/3_27_0/GPL-2_0-only_AND_LGPL-2_1-or-later"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/relationship/38e919cb3cc68a382f821e21f5560c52","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/relationship/38e919cb3cc68a382f821e21f5560c52"}],"from":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010022","http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010023","http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010024","http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010025"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/relationship/6932260c298154a0b1d5307d99321d16","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/relationship/6932260c298154a0b1d5307d99321d16"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"],"scope":"build"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/relationship/818b9dd42e0ecad1e2a7c90fbc8c512b","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/relationship/818b9dd42e0ecad1e2a7c90fbc8c512b"}],"from":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode","relationshipType":"contains","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/1","http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/2","http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode/file/3"]},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/vex-not-affected/66a78a4d4e3b81b68eef6201866134e9","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/vex-not-affected/66a78a4d4e3b81b68eef6201866134e9"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010022","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/vex-not-affected/79bc7306e17cfb7819d416315e0bf068","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/vex-not-affected/79bc7306e17cfb7819d416315e0bf068"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010024","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/vex-not-affected/a90442fcf9dd3cdf4c9d9e0f2e04ca39","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/vex-not-affected/a90442fcf9dd3cdf4c9d9e0f2e04ca39"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010025","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"],"security_vexVersion":"1.0.0","security_impactStatement":"Allows for ASLR bypass so can bypass some hardening, not an exploit in itself, may allow easier access for another. 'ASLR bypass itself is not a vulnerability.'"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/vex-not-affected/f380f87030e6ea2a70a7f937d7b2000e","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/bd459ff1ff4ceef7fa87b38ac3e03ae612e3c24b12f6d90d31dd32fbd246ca7e/glibc/UNIHASH/vex-not-affected/f380f87030e6ea2a70a7f937d7b2000e"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8bcc50109a89a2a5b45d13a5cd9a3fb7e276afd2bf762de4772a02f224c2f6bf/glibc/UNIHASH/vulnerability/CVE-2019-1010023","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/glibc-086907e2-5516-5638-9df3-b3863651f374/ff0fa986562cc19d03a0a0e5521e3c1c969d98d81d02655a677ed907182d7d1f/package/tzcode"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."}]}