Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
fd87a94a by Moritz Muehlenhoff at 2020-11-19T21:20:23+01:00
c-ares fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -52015,7 +52015,7 @@ CVE-2020-8279 (Missing validation of server
certificates for out-going connectio
CVE-2020-8278 (Improper access control in Nextcloud Social app version 0.3.1
allowed ...)
TODO: check
CVE-2020-8277 (A Node.js application that allows an attacker to trigger a DNS
request ...)
- - c-ares <unfixed>
+ - c-ares 1.17.1-1
[buster] - c-ares <not-affected> (Introduced in 1.16)
[stretch] - c-ares <not-affected> (Introduced in 1.16)
NOTE: Originally reported for nodes, which bundles c-ares:
https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/#denial-of-service-through-dns-request-cve-2020-8277
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits