[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-16117/evolution-data-server

Salvatore Bonaccorso carnil at debian.org
Mon Aug 24 19:42:52 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7f6535e4 by Salvatore Bonaccorso at 2020-08-24T20:42:40+02:00
Mark CVE-2020-16117/evolution-data-server

To exploit the issue a malicious server is required and it "just" causes
a crash of the client. The fix can thus be included in an upcoming point
release.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17150,6 +17150,7 @@ CVE-2020-16118 (In GNOME Balsa before 2.6.0, a malicious server operator or man
 CVE-2020-16117 (In GNOME evolution-data-server before 3.35.91, a malicious server can  ...)
 	{DLA-2309-1}
 	- evolution-data-server 3.36.0-1
+	[buster] - evolution-data-server <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5
 	NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7
 	NOTE: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f6535e4ece0c94f420625731288d587ca36fb75

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f6535e4ece0c94f420625731288d587ca36fb75
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200824/463f57f4/attachment.html>


More information about the debian-security-tracker-commits mailing list