[Git][security-tracker-team/security-tracker][master] Add CVE-2020-11997

Salvatore Bonaccorso carnil at debian.org
Wed Jan 20 08:26:25 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d34a414 by Salvatore Bonaccorso at 2021-01-20T09:25:59+01:00
Add CVE-2020-11997

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -59525,7 +59525,9 @@ CVE-2020-11998 (A regression has been introduced in the commit preventing JMX re
 	- activemq <not-affected> (Only affects 5.15.12)
 	NOTE: http://activemq.apache.org/security-advisories.data/CVE-2020-11998-announcement.txt
 CVE-2020-11997 (Apache Guacamole 1.2.0 and earlier do not consistently restrict access ...)
-	TODO: check
+	- guacamole-server 1.3.0-1
+	NOTE: https://lists.apache.org/thread.html/r1a9ae9d1608c9f846875c4191cd738f95543d1be06b52dc1320e8117%40%3Cannounce.guacamole.apache.org%3E
+	TODO: check details, both guacamole-client and guacamole-server affected?
 CVE-2020-11996 (A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat  ...)
 	{DSA-4727-1 DLA-2279-1}
 	- tomcat9 9.0.36-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d34a414cc13fc539fe2c2de1836842253f8ca07

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d34a414cc13fc539fe2c2de1836842253f8ca07
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210120/7ade8cec/attachment.html>


More information about the debian-security-tracker-commits mailing list