[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2020-26262/coturn

Salvatore Bonaccorso carnil at debian.org
Mon Jan 11 10:38:41 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4f86923f by Salvatore Bonaccorso at 2021-01-11T11:33:45+01:00
Add CVE-2020-26262/coturn

- - - - -
46a3e602 by Salvatore Bonaccorso at 2021-01-11T11:34:36+01:00
Add coturn to needed update lists

- - - - -


3 changed files:

- data/CVE/list
- data/dla-needed.txt
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -23096,6 +23096,16 @@ CVE-2020-26263 (tlslite-ng is an open source python library that implements SSL
 	NOTE: https://github.com/tlsfuzzer/tlslite-ng/pull/439
 CVE-2020-26262
 	RESERVED
+	- coturn <unfixed>
+	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
+	NOTE: https://github.com/coturn/coturn/commit/ff5e5478a3e1b426bad053828099403cfc5c1f5f
+	NOTE: https://github.com/coturn/coturn/commit/af50d63a152cd9505d38f02bc552848748805e7b
+	NOTE: https://github.com/coturn/coturn/commit/6c774b9fb8d9d76576ece10a6429172ed3800466
+	NOTE: https://github.com/coturn/coturn/commit/560684c894498285f9e4271f3c924ebf01f36307
+	NOTE: https://github.com/coturn/coturn/commit/649cbf966181846ecdd7847e4543dd287a78d295
+	NOTE: https://github.com/coturn/coturn/commit/9c7deff4b8ed8c323c87b9ede75481bd6bc3154d
+	NOTE: https://github.com/coturn/coturn/commit/dd0ffdb51a4cddaf1d6662079fa91f6f32bd26a8
+	NOTE: https://github.com/coturn/coturn/commit/d84028b6dbc9eb7d3f8828ec37ae02a0963257b6
 CVE-2020-26261 (jupyterhub-systemdspawner enables JupyterHub to spawn single-user note ...)
 	NOT-FOR-US: JupyterHub
 CVE-2020-26260 (BookStack is a platform for storing and organising information and doc ...)


=====================================
data/dla-needed.txt
=====================================
@@ -33,6 +33,8 @@ condor
   NOTE: 20200712: Requested input on path forward from debian-lts at l.d.o (roberto)
   NOTE: 20200727: Waiting on maintainer feedback: https://lists.debian.org/debian-lts/2020/07/msg00108.html (roberto)
 --
+coturn (Emilio)
+--
 f2fs-tools
   NOTE: 20200815: About CVE-2020-6070. The fix got introduced between 1.12.0 and 1.13.0, but it is not trivial to
   NOTE: 20200815: to detect which of the patches correlates to the CVE. Contacting upstream might be necessary. (sunweaver)


=====================================
data/dsa-needed.txt
=====================================
@@ -16,6 +16,8 @@ ansible
 --
 chromium
 --
+coturn (carnil)
+--
 knot-resolver
   Santiago Ruano Rincón proposed a debdiff for review
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0f24146aa0901e567e847747944c4f3560ac0fa3...46a3e6027e3ce26fd6a654a3c171deb678e9d923

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0f24146aa0901e567e847747944c4f3560ac0fa3...46a3e6027e3ce26fd6a654a3c171deb678e9d923
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210111/5d6c109b/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list