Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1018308

Bug#965184: CVE-2020-15719

From Moritz Muehlenhoff <jmm@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#965184: CVE-2020-15719
Date 2020-07-17 12:50 +0200
Message-ID <Atw6d-3s9-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Source: openldap
Severity: important
Tags: security

Hi,
CVE-2020-15719 was assigned to an issue in OpenLDAP found by Red Hat:
https://bugzilla.redhat.com/show_bug.cgi?id=1740070

The underlying OpenLDAP bug is restricted, though:
https://bugs.openldap.org/show_bug.cgi?id=9266

The patch applied by Red Hat is
https://git.centos.org/rpms/openldap/raw/67459960064be9d226d57c5f82aaba0929876813/f/SOURCES/openldap-tlso-dont-check-cn-when-bad-san.patch
bug given that 1740070 is restricted I'm not sure if it affects the
Debian OpenLDAP packages or not (as we sue GNUTLS instead of OpenSSL)

Cheers,
        Moritz

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#965184: CVE-2020-15719 Moritz Muehlenhoff <jmm@debian.org> - 2020-07-17 12:50 +0200
  Bug#965184: CVE-2020-15719 Ryan Tandy <ryan@nardis.ca> - 2020-07-17 18:20 +0200
    Bug#965184: CVE-2020-15719 Moritz Mühlenhoff <jmm@inutil.org> - 2020-07-22 16:40 +0200

csiph-web