Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2c067811 by Salvatore Bonaccorso at 2020-09-06T21:16:59+02:00
Add Debian bug reference covering four wolfssl CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1229,7 +1229,7 @@ CVE-2020-24616 (FasterXML jackson-databind 2.x before 
2.9.10.6 mishandles the in
 CVE-2020-24615
        RESERVED
 CVE-2020-24613 (wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the 
WAIT_CERT_C ...)
-       - wolfssl <unfixed>
+       - wolfssl <unfixed> (bug #969663)
        NOTE: 
https://research.nccgroup.com/2020/08/24/technical-advisory-wolfssl-tls-1-3-client-man-in-the-middle-attack/
 CVE-2020-24612 (An issue was discovered in the selinux-policy (aka Reference 
Policy) p ...)
        - refpolicy <not-affected> (Debian package doesn't ship pam-u2f config)
@@ -1286,7 +1286,7 @@ CVE-2020-24587
 CVE-2020-24586
        RESERVED
 CVE-2020-24585 (An issue was discovered in the DTLS handshake implementation 
in wolfSS ...)
-       - wolfssl <unfixed>
+       - wolfssl <unfixed> (bug #969663)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/3219
        NOTE: 
https://github.com/wolfSSL/wolfssl/commit/3be7f3ea3a56d178acf0f7f84ee4ae8cbfee8915
 (v4.5.0-stable)
 CVE-2020-24584 (An issue was discovered in Django 2.2 before 2.2.16, 3.0 
before 3.0.10 ...)
@@ -20486,7 +20486,7 @@ CVE-2020-15311 (Stash 1.0.3 allows SQL Injection via 
the downloadmp3.php downloa
 CVE-2020-15310
        RESERVED
 CVE-2020-15309 (An issue was discovered in wolfSSL before 4.5.0, when single 
precision ...)
-       - wolfssl <unfixed>
+       - wolfssl <unfixed> (bug #969663)
        NOTE: https://github.com/wolfSSL/wolfssl/releases/tag/v4.5.0-stable
 CVE-2020-15308 (Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 
allows post-a ...)
        NOT-FOR-US: Support Incident Tracker
@@ -27895,7 +27895,7 @@ CVE-2020-12458 (An information-disclosure flaw was 
found in Grafana through 6.7.
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1827765
        NOTE: https://github.com/grafana/grafana/issues/8283
 CVE-2020-12457 (An issue was discovered in wolfSSL before 4.5.0. It mishandles 
the cha ...)
-       - wolfssl <unfixed>
+       - wolfssl <unfixed> (bug #969663)
        NOTE: 
https://github.com/wolfSSL/wolfssl/commit/df1b7f34f173cfc2968ce12e8fcd2fd8bcc61a59
 (v4.5.0-stable)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/2927
 CVE-2020-12456 (A remote code execution vulnerability in Mitel MiVoice Connect 
Client  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c0678112f57e9001ce61279f43997d78744e0d1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c0678112f57e9001ce61279f43997d78744e0d1
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to