Bug#978931: gssproxy: CVE-2020-12658

2021-01-05 Thread Robbie Harwood (frozencemetery)
Package: gssproxy Followup-For: Bug #978931 X-Debbugs-Cc: rharw...@club.cc.cmu.edu Control: severity -1 minor Control: close -1 Hi, I (upstream and downstream maintainer) do not believe this is CVE-worthy and have filed dispute claim with Mitre. The code change in question only happens in a

Bug#978931: gssproxy: CVE-2020-12658

2021-01-05 Thread rharwood
Package: gssproxy Followup-For: Bug #978931 Control: tags -1 - security

Bug#978931: gssproxy: CVE-2020-12658

2020-12-31 Thread Salvatore Bonaccorso
Source: gssproxy Version: 0.8.2-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for gssproxy. CVE-2020-12658[0]: | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex | before pthread