From b84e1d89227b9636b449e379d9d2a0bdc5015ca0 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 7 Apr 2020 21:02:46 +0200 Subject: Update information on CVE-2020-1759/ceph --- data/CVE/list.2020 | 3 +++ 1 file changed, 3 insertions(+) diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index dd18c598fc..1387c832e5 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -21113,6 +21113,9 @@ CVE-2020-1760 [header-splitting in RGW GetObject has a possible XSS] CVE-2020-1759 [ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions] RESERVED - ceph + [buster] - ceph (Vulnerable code not present) + [stretch] - ceph (Vulnerable code not present) + [jessie] - ceph (Vulnerable code not present) NOTE: Introduced with: https://github.com/ceph/ceph-ci/commit/fe387e02b11df98357d8cdbfa3b1f1d5f2bb3f74 NOTE: Fixed by: https://github.com/ceph/ceph-ci/commit/84d2e215969cde830b086d11544aeb3666614211 NOTE: Fixed by: https://github.com/ceph/ceph-ci/commit/659ec7dc6e30fe961832f813da007f49e603a33d -- cgit v1.2.3