Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2c067811 by Salvatore Bonaccorso at 2020-09-06T21:16:59+02:00
Add Debian bug reference covering four wolfssl CVEs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1229,7 +1229,7 @@ CVE-2020-24616 (FasterXML jackson-databind 2.x before
2.9.10.6 mishandles the in
CVE-2020-24615
RESERVED
CVE-2020-24613 (wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the
WAIT_CERT_C ...)
- - wolfssl <unfixed>
+ - wolfssl <unfixed> (bug #969663)
NOTE:
https://research.nccgroup.com/2020/08/24/technical-advisory-wolfssl-tls-1-3-client-man-in-the-middle-attack/
CVE-2020-24612 (An issue was discovered in the selinux-policy (aka Reference
Policy) p ...)
- refpolicy <not-affected> (Debian package doesn't ship pam-u2f config)
@@ -1286,7 +1286,7 @@ CVE-2020-24587
CVE-2020-24586
RESERVED
CVE-2020-24585 (An issue was discovered in the DTLS handshake implementation
in wolfSS ...)
- - wolfssl <unfixed>
+ - wolfssl <unfixed> (bug #969663)
NOTE: https://github.com/wolfSSL/wolfssl/pull/3219
NOTE:
https://github.com/wolfSSL/wolfssl/commit/3be7f3ea3a56d178acf0f7f84ee4ae8cbfee8915
(v4.5.0-stable)
CVE-2020-24584 (An issue was discovered in Django 2.2 before 2.2.16, 3.0
before 3.0.10 ...)
@@ -20486,7 +20486,7 @@ CVE-2020-15311 (Stash 1.0.3 allows SQL Injection via
the downloadmp3.php downloa
CVE-2020-15310
RESERVED
CVE-2020-15309 (An issue was discovered in wolfSSL before 4.5.0, when single
precision ...)
- - wolfssl <unfixed>
+ - wolfssl <unfixed> (bug #969663)
NOTE: https://github.com/wolfSSL/wolfssl/releases/tag/v4.5.0-stable
CVE-2020-15308 (Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2
allows post-a ...)
NOT-FOR-US: Support Incident Tracker
@@ -27895,7 +27895,7 @@ CVE-2020-12458 (An information-disclosure flaw was
found in Grafana through 6.7.
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1827765
NOTE: https://github.com/grafana/grafana/issues/8283
CVE-2020-12457 (An issue was discovered in wolfSSL before 4.5.0. It mishandles
the cha ...)
- - wolfssl <unfixed>
+ - wolfssl <unfixed> (bug #969663)
NOTE:
https://github.com/wolfSSL/wolfssl/commit/df1b7f34f173cfc2968ce12e8fcd2fd8bcc61a59
(v4.5.0-stable)
NOTE: https://github.com/wolfSSL/wolfssl/pull/2927
CVE-2020-12456 (A remote code execution vulnerability in Mitel MiVoice Connect
Client ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c0678112f57e9001ce61279f43997d78744e0d1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c0678112f57e9001ce61279f43997d78744e0d1
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits