[Git][security-tracker-team/security-tracker][master] CVE-2020-25660: Add complete list of upstream commits
Salvatore Bonaccorso
carnil at debian.org
Thu Nov 19 21:17:01 GMT 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
008697ba by Salvatore Bonaccorso at 2020-11-19T22:16:28+01:00
CVE-2020-25660: Add complete list of upstream commits
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10454,8 +10454,12 @@ CVE-2020-25660 [cephx authentication protocol does not verify ceph clients corre
NOTE: https://www.openwall.com/lists/oss-security/2020/11/17/4
NOTE: Proposed patches: https://www.openwall.com/lists/oss-security/2020/11/17/3
NOTE: Introduced by: https://github.com/ceph/ceph/commit/321548010578d6ff7bbf2e5ce8a550008b131423 (v15.1.0, backported to v14.2.5)
- NOTE: Fixed by: https://github.com/ceph/ceph/commit/4a82c72e3bdddcb625933e83af8b50a444b961f1 (15.1.x)
- NOTE: Fixed by: https://github.com/ceph/ceph/commit/2927fd91d41e505237cc73f9700e5c6a63e5cb4f (14.2.x)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/6c14c2fb5650426285428dfe6ca1597e5ea1d07d (15.2.6)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/1316c82aae8c51b3fe10d8a8f0a87b60db54ee16 (15.2.6)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/bafdfec8f974f1a3f7d404bcfd0a4cfad784937d (15.2.6)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/2927fd91d41e505237cc73f9700e5c6a63e5cb4f (14.2.14)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/4c11203122d729c832a645c9e3f5092db4963840 (14.2.14)
+ NOTE: Fixed by: https://github.com/ceph/ceph/commit/bb5d3d58bfcae96d2e5f796eaa74fc0987f79e77 (14.2.14)
CVE-2020-25659 [bleichenbacher timing oracle attack against RSA decryption]
RESERVED
- python-cryptography 3.2.1-1 (bug #973247)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/008697ba9717f9a0e45554a46c7adf61c856120a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/008697ba9717f9a0e45554a46c7adf61c856120a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201119/f512da3f/attachment.html>
More information about the debian-security-tracker-commits
mailing list