summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2020-01-30 08:10:19 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2020-01-30 08:13:05 +0100
commitbf40e35d730494963d31413d09b73aa24e8a49d6 (patch)
treea2915820b6af94e9321c51583a8f9e23ecc12cc4
parentc19536767d0e0fa9a7f76ed19f19eadcf76dee28 (diff)
Add CVE-2020-7238/netty
-rw-r--r--data/CVE/list.20205
1 files changed, 4 insertions, 1 deletions
diff --git a/data/CVE/list.2020 b/data/CVE/list.2020
index 61f7c0865d..f2dbb9df32 100644
--- a/data/CVE/list.2020
+++ b/data/CVE/list.2020
@@ -2417,7 +2417,10 @@ CVE-2020-7240 (Meinberg Lantime M300 and M1000 devices allow attackers (with pri
CVE-2020-7239 (The conversation-watson plugin before 0.8.21 for WordPress has a DOM-b ...)
NOT-FOR-US: conversation-watson plugin for WordPress
CVE-2020-7238 (Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1796225
+ NOTE: https://github.com/jdordonezn/CVE-2020-72381/issues/1
+ NOTE: Issue exists because of incomplete fix for CVE-2019-16869.
CVE-2020-7237 (Cacti 1.2.8 allows Remote Code Execution (by privileged users) via she ...)
- cacti <unfixed> (bug #949997)
[jessie] - cacti <not-affected> (Vulnerable code introduced later)

© 2014-2024 Faster IT GmbH | imprint | privacy policy