[Git][security-tracker-team/security-tracker][master] Patch for CVE-2020-1773 implements a new way for random number

Abhijith PA abhijith at debian.org
Sat Apr 11 08:13:31 BST 2020



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cab123bd by Abhijith PA at 2020-04-11T12:37:03+05:30
Patch for CVE-2020-1773 implements a new way for random number
generation which need a lot of perl modules to be backported.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25021,6 +25021,7 @@ CVE-2020-1773 (An attacker with the ability to generate session IDs or password
 	- otrs2 6.0.27-1
 	[buster] - otrs2 <no-dsa> (Non-free not supported)
 	[stretch] - otrs2 <no-dsa> (Non-free not supported)
+	[jessie] - otrs2 <no-dsa> (Too intrusive to backport)
 	NOTE: https://otrs.com/release-notes/otrs-security-advisory-2020-10/
 	NOTE: Fixed in 7.0.16, 6.0.27, 5.0.42
 	NOTE: OTRS6: https://github.com/OTRS/otrs/commit/ab253734bc211541309b9f8ea2b8b70389c4a64e



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cab123bd7c49c77100a0e5c92dec628f32d858c4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cab123bd7c49c77100a0e5c92dec628f32d858c4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200411/71b181ad/attachment.html>


More information about the debian-security-tracker-commits mailing list