Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
da99da47 by Moritz Muehlenhoff at 2020-06-02T20:15:46+02:00
yaws/erlang tracking (a bit of a hack, but works)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1904,12 +1904,14 @@ CVE-2020-12874 (Veritas APTARE versions prior to 10.4 
included code that bypasse
 CVE-2020-12873
        RESERVED
 CVE-2020-12872 (yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads 
obsolete TLS  ...)
-       - yaws <unfixed> (low; bug #961422)
-       [buster] - yaws <no-dsa> (Minor issue)
+       - yaws 1:21.2.6+dfsg-1 (low)
        [stretch] - yaws <no-dsa> (Minor issue)
        [jessie] - yaws <no-dsa> (Minor issue)
        NOTE: https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70
        NOTE: https://github.com/erlyaws/yaws/issues/402
+       NOTE: In Debian yaws uses the cipher settings from erlang, mark the 
version which
+       NOTE: landed in Buster as fixed (although it was possibly fixed earlier 
between
+       NOTE: Stretch and Buster
 CVE-2020-12871
        RESERVED
 CVE-2020-12870



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to