[Git][security-tracker-team/security-tracker][master] Add two rhonabwy issues fixed in unstable (#993866)

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 11 10:21:40 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a799ddc6 by Salvatore Bonaccorso at 2021-09-11T11:20:56+02:00
Add two rhonabwy issues fixed in unstable (#993866)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -401,6 +401,12 @@ CVE-2021-40685
 	RESERVED
 CVE-2021-40684
 	RESERVED
+CVE-2021-XXXX [jwe cbc tag computation error]
+	- rhonabwy 0.9.13-4 (bug #993866)
+	NOTE: https://github.com/babelouest/rhonabwy/commit/996d935540c2c171c7678f14b8178d9ce87db9ac (v1.0.0)
+CVE-2021-XXXX [jws alg:none signature verification issue]
+	- rhonabwy 0.9.13-4 (bug #993866)
+	NOTE: https://github.com/babelouest/rhonabwy/commit/ff9ecad4c9a031c8369acde67ea52d558899e51e (v1.0.0)
 CVE-2021-40818 (scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer ov ...)
 	- glewlwyd 2.5.2-3 (bug #993867)
 	NOTE: https://github.com/babelouest/glewlwyd/commit/0efd112bb62f566877750ad62ee828bff579b4e2



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a799ddc65dcfbe498f41c7520888611603fefa80

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a799ddc65dcfbe498f41c7520888611603fefa80
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210911/0d74ad7a/attachment.htm>


More information about the debian-security-tracker-commits mailing list