[Git][security-tracker-team/security-tracker][master] Add CVE-2019-3685/osc (mark for now as undetermined)
Salvatore Bonaccorso
carnil at debian.org
Wed Aug 7 08:22:16 BST 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ce33a5bf by Salvatore Bonaccorso at 2019-08-07T07:21:01Z
Add CVE-2019-3685/osc (mark for now as undetermined)
The issue might affect src:osc only starting from upstream 0.165.0 but
the Red Hat report at
https://bugzilla.redhat.com/show_bug.cgi?id=1737797 does not provide
enough information to be sure on it. For now mark it as undetermined and
try to find out more on the issue.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -29935,8 +29935,10 @@ CVE-2019-3687
RESERVED
CVE-2019-3686
RESERVED
-CVE-2019-3685
+CVE-2019-3685 [Fails to adequately verify TLS certificates allowing for a man in the middle attack]
RESERVED
+ - osc <undetermined>
+ TODO: check, might affect only 0.165.0 through 0.165.2, but not earlier versions
CVE-2019-3684 (SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a71 ...)
NOT-FOR-US: SUSE Manager
CVE-2019-3683
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ce33a5bf184c3ddaad6252d9355df70825c32147
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ce33a5bf184c3ddaad6252d9355df70825c32147
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190807/6b6e97e6/attachment.html>
More information about the debian-security-tracker-commits
mailing list