Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
804d60cb by Salvatore Bonaccorso at 2021-06-12T17:14:21+02:00
Add/Update notes for CVE-2020-13950
Upstream is clear here and claims 2.4.41 is the first version affected.
Whilst the patch would apply it causes errors, so a previous change
might be introducing the vulnerability. But there is no further
information available for now.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -78258,7 +78258,8 @@ CVE-2020-13950 (Apache HTTP Server versions 2.4.41 to
2.4.46 mod_proxy_http can
[experimental] - apache2 2.4.48-1
- apache2 2.4.46-6
NOTE:
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-13950
- NOTE: https://svn.apache.org/r1678771
+ NOTE: Fixed by: https://svn.apache.org/r1678771
+ TODO: check why this only a problem starting in 2.4.41
CVE-2020-13949 (In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could
send sho ...)
- thrift <unfixed> (bug #988949)
[bullseye] - thrift <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits