[Git][security-tracker-team/security-tracker][master] Add CVE-2020-7212/python-urllib3
Salvatore Bonaccorso
carnil at debian.org
Sat Mar 7 07:20:13 GMT 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d3558372 by Salvatore Bonaccorso at 2020-03-07T08:19:21+01:00
Add CVE-2020-7212/python-urllib3
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6682,8 +6682,15 @@ CVE-2020-7214
RESERVED
CVE-2020-7213 (Parallels 13 uses cleartext HTTP as part of the update process, allowi ...)
NOT-FOR-US: Parallels
-CVE-2020-7212
+CVE-2020-7212 [denial of service (CPU consumption) because of inefficient algorithm in _encode_invalid_chars function]
RESERVED
+ - python-urllib3 <unfixed>
+ [buster] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+ [stretch] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+ [jessie] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/urllib3/urllib3/pull/1787
+ NOTE: Introduced by: https://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221a (1.25.2)
+ NOTE: Fixed by: https://github.com/urllib3/urllib3/commit/a2697e7c6b275f05879b60f593c5854a816489f0 (1.25.8)
CVE-2020-7211 (tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ ...)
- libslirp <unfixed> (unimportant)
NOTE: https://bugs.launchpad.net/qemu/+bug/1812451
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d35583723f309a0255eb3b510a18e2c3ee1002f3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d35583723f309a0255eb3b510a18e2c3ee1002f3
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200307/3855c72f/attachment.html>
More information about the debian-security-tracker-commits
mailing list