[Git][security-tracker-team/security-tracker][master] c-ares fixed in sid

Moritz Muehlenhoff jmm at debian.org
Thu Nov 19 20:20:35 GMT 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd87a94a by Moritz Muehlenhoff at 2020-11-19T21:20:23+01:00
c-ares fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -52015,7 +52015,7 @@ CVE-2020-8279 (Missing validation of server certificates for out-going connectio
 CVE-2020-8278 (Improper access control in Nextcloud Social app version 0.3.1 allowed  ...)
 	TODO: check
 CVE-2020-8277 (A Node.js application that allows an attacker to trigger a DNS request ...)
-	- c-ares <unfixed>
+	- c-ares 1.17.1-1
 	[buster] - c-ares <not-affected> (Introduced in 1.16)
 	[stretch] - c-ares <not-affected> (Introduced in 1.16)
 	NOTE: Originally reported for nodes, which bundles c-ares: https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/#denial-of-service-through-dns-request-cve-2020-8277



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201119/f81c763a/attachment.html>


More information about the debian-security-tracker-commits mailing list