[Git][security-tracker-team/security-tracker][master] yaws/erlang tracking (a bit of a hack, but works)

Moritz Muehlenhoff jmm at debian.org
Tue Jun 2 19:16:13 BST 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
da99da47 by Moritz Muehlenhoff at 2020-06-02T20:15:46+02:00
yaws/erlang tracking (a bit of a hack, but works)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1904,12 +1904,14 @@ CVE-2020-12874 (Veritas APTARE versions prior to 10.4 included code that bypasse
 CVE-2020-12873
 	RESERVED
 CVE-2020-12872 (yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS  ...)
-	- yaws <unfixed> (low; bug #961422)
-	[buster] - yaws <no-dsa> (Minor issue)
+	- yaws 1:21.2.6+dfsg-1 (low)
 	[stretch] - yaws <no-dsa> (Minor issue)
 	[jessie] - yaws <no-dsa> (Minor issue)
 	NOTE: https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70
 	NOTE: https://github.com/erlyaws/yaws/issues/402
+	NOTE: In Debian yaws uses the cipher settings from erlang, mark the version which
+	NOTE: landed in Buster as fixed (although it was possibly fixed earlier between
+	NOTE: Stretch and Buster
 CVE-2020-12871
 	RESERVED
 CVE-2020-12870



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da99da47f6c7d86f85caa8382fcffc6f6de55b70
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200602/b38bdd82/attachment.html>


More information about the debian-security-tracker-commits mailing list