[Git][security-tracker-team/security-tracker][master] yaws/erlang tracking (a bit of a hack, but works)
Moritz Muehlenhoff
jmm at debian.org
Tue Jun 2 19:16:13 BST 2020
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
da99da47 by Moritz Muehlenhoff at 2020-06-02T20:15:46+02:00
yaws/erlang tracking (a bit of a hack, but works)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1904,12 +1904,14 @@ CVE-2020-12874 (Veritas APTARE versions prior to 10.4 included code that bypasse
CVE-2020-12873
RESERVED
CVE-2020-12872 (yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ...)
- - yaws <unfixed> (low; bug #961422)
- [buster] - yaws <no-dsa> (Minor issue)
+ - yaws 1:21.2.6+dfsg-1 (low)
[stretch] - yaws <no-dsa> (Minor issue)
[jessie] - yaws <no-dsa> (Minor issue)
NOTE: https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70
NOTE: https://github.com/erlyaws/yaws/issues/402
+ NOTE: In Debian yaws uses the cipher settings from erlang, mark the version which
+ NOTE: landed in Buster as fixed (although it was possibly fixed earlier between
+ NOTE: Stretch and Buster
CVE-2020-12871
RESERVED
CVE-2020-12870
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200602/b38bdd82/attachment.html>
More information about the debian-security-tracker-commits
mailing list