Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
804d60cb by Salvatore Bonaccorso at 2021-06-12T17:14:21+02:00
Add/Update notes for CVE-2020-13950

Upstream is clear here and claims 2.4.41 is the first version affected.
Whilst the patch would apply it causes errors, so a previous change
might be introducing the vulnerability. But there is no further
information available for now.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -78258,7 +78258,8 @@ CVE-2020-13950 (Apache HTTP Server versions 2.4.41 to 
2.4.46 mod_proxy_http can
        [experimental] - apache2 2.4.48-1
        - apache2 2.4.46-6
        NOTE: 
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-13950
-       NOTE: https://svn.apache.org/r1678771
+       NOTE: Fixed by: https://svn.apache.org/r1678771
+       TODO: check why this only a problem starting in 2.4.41
 CVE-2020-13949 (In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could 
send sho ...)
        - thrift <unfixed> (bug #988949)
        [bullseye] - thrift <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to