Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
da99da47 by Moritz Muehlenhoff at 2020-06-02T20:15:46+02:00
yaws/erlang tracking (a bit of a hack, but works)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1904,12 +1904,14 @@ CVE-2020-12874 (Veritas APTARE versions prior to 10.4
included code that bypasse
CVE-2020-12873
RESERVED
CVE-2020-12872 (yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads
obsolete TLS ...)
- - yaws <unfixed> (low; bug #961422)
- [buster] - yaws <no-dsa> (Minor issue)
+ - yaws 1:21.2.6+dfsg-1 (low)
[stretch] - yaws <no-dsa> (Minor issue)
[jessie] - yaws <no-dsa> (Minor issue)
NOTE: https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70
NOTE: https://github.com/erlyaws/yaws/issues/402
+ NOTE: In Debian yaws uses the cipher settings from erlang, mark the
version which
+ NOTE: landed in Buster as fixed (although it was possibly fixed earlier
between
+ NOTE: Stretch and Buster
CVE-2020-12871
RESERVED
CVE-2020-12870
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits