[Git][security-tracker-team/security-tracker][master] Add/Update notes for CVE-2020-13950

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jun 12 16:16:26 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
804d60cb by Salvatore Bonaccorso at 2021-06-12T17:14:21+02:00
Add/Update notes for CVE-2020-13950

Upstream is clear here and claims 2.4.41 is the first version affected.
Whilst the patch would apply it causes errors, so a previous change
might be introducing the vulnerability. But there is no further
information available for now.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -78258,7 +78258,8 @@ CVE-2020-13950 (Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can
 	[experimental] - apache2 2.4.48-1
 	- apache2 2.4.46-6
 	NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-13950
-	NOTE: https://svn.apache.org/r1678771
+	NOTE: Fixed by: https://svn.apache.org/r1678771
+	TODO: check why this only a problem starting in 2.4.41
 CVE-2020-13949 (In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send sho ...)
 	- thrift <unfixed> (bug #988949)
 	[bullseye] - thrift <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/804d60cb8d869b2a9eb2453579d32e9cab2d5c5f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210612/ff7cb28c/attachment.htm>


More information about the debian-security-tracker-commits mailing list