Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: fd87a94a by Moritz Muehlenhoff at 2020-11-19T21:20:23+01:00 c-ares fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -52015,7 +52015,7 @@ CVE-2020-8279 (Missing validation of server certificates for out-going connectio CVE-2020-8278 (Improper access control in Nextcloud Social app version 0.3.1 allowed ...) TODO: check CVE-2020-8277 (A Node.js application that allows an attacker to trigger a DNS request ...) - - c-ares <unfixed> + - c-ares 1.17.1-1 [buster] - c-ares <not-affected> (Introduced in 1.16) [stretch] - c-ares <not-affected> (Introduced in 1.16) NOTE: Originally reported for nodes, which bundles c-ares: https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/#denial-of-service-through-dns-request-cve-2020-8277 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd87a94a567280ca52d125d997aab1b8cd5d7b04 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits