[Git][security-tracker-team/security-tracker][master] Mark CVE-2014-3566/netsurf as fixed with 3.6-1

Salvatore Bonaccorso carnil at debian.org
Wed Jul 29 10:33:11 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8120936f by Salvatore Bonaccorso at 2020-07-29T11:32:06+02:00
Mark CVE-2014-3566/netsurf as fixed with 3.6-1

Upstream commit b2242c57e17f ("HTTPS: disable all SSL versions; emit
fallback SCSV on downgrade.") in 3.3 disables SSLv3. Later on commit
a8bf9b05aa94 ("HTTPS: restrict ciphersuites") in 3.8 restricts further
the cipyersuites.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -275856,7 +275856,7 @@ CVE-2014-3566 (The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other
 	[squeeze] - matrixssl <no-dsa> (Minor issue)
 	[wheezy] - matrixssl <no-dsa> (Minor issue)
 	- midori <unfixed> (unimportant)
-	- netsurf <unfixed> (unimportant)
+	- netsurf 3.6-1 (unimportant)
 	- nss 2:3.17.1-1
 	[squeeze] - nss <no-dsa> (Upstream doesn't plan to disable SSLv3, stick with that)
 	[wheezy] - nss <no-dsa> (Upstream doesn't plan to disable SSLv3, stick with that)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8120936f9df6c6a7cfb541dd7742e4705763f2d3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8120936f9df6c6a7cfb541dd7742e4705763f2d3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200729/e0f6f986/attachment.html>


More information about the debian-security-tracker-commits mailing list