[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-16117/evolution-data-server
Salvatore Bonaccorso
carnil at debian.org
Mon Aug 24 19:42:52 BST 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7f6535e4 by Salvatore Bonaccorso at 2020-08-24T20:42:40+02:00
Mark CVE-2020-16117/evolution-data-server
To exploit the issue a malicious server is required and it "just" causes
a crash of the client. The fix can thus be included in an upcoming point
release.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -17150,6 +17150,7 @@ CVE-2020-16118 (In GNOME Balsa before 2.6.0, a malicious server operator or man
CVE-2020-16117 (In GNOME evolution-data-server before 3.35.91, a malicious server can ...)
{DLA-2309-1}
- evolution-data-server 3.36.0-1
+ [buster] - evolution-data-server <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5
NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7
NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f6535e4ece0c94f420625731288d587ca36fb75
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f6535e4ece0c94f420625731288d587ca36fb75
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200824/463f57f4/attachment.html>
More information about the debian-security-tracker-commits
mailing list