osc: CVE-2019-3685

Related Vulnerabilities: CVE-2019-3685  

Debian Bug report logs - #941667
osc: CVE-2019-3685

Package: osc; Maintainer for osc is RPM packaging team <team+pkg-rpm@tracker.debian.org>; Source for osc is src:osc (PTS, buildd, popcon).

Reported by: Sylvain Beucler <beuc@beuc.net>

Date: Thu, 3 Oct 2019 14:54:02 UTC

Severity: important

Tags: security

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, RPM packaging team <team+pkg-rpm@tracker.debian.org>:
Bug#941667; Package osc. (Thu, 03 Oct 2019 14:54:05 GMT) (full text, mbox, link).


Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, RPM packaging team <team+pkg-rpm@tracker.debian.org>. (Thu, 03 Oct 2019 14:54:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Sylvain Beucler <beuc@beuc.net>
To: submit@bugs.debian.org
Subject: CVE-2019-3685
Date: Thu, 3 Oct 2019 16:50:45 +0200
Package: osc
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for osc.

CVE-2019-3685[0]:
Fails to adequately verify TLS certificates allowing for a man in the middle attack

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Sadly, little information is known at the moment:

[0] https://security-tracker.debian.org/tracker/CVE-2019-3685
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3685
    https://bugzilla.redhat.com/show_bug.cgi?id=1737797

To the least, it would help to know which versions are affected.
Please adjust the affected versions in the BTS as needed.

Cheers!
Sylvain Beucler
Debian LTS Team



Changed Bug title to 'osc: CVE-2019-3685' from 'CVE-2019-3685'. Request was from Sylvain Beucler <beuc@beuc.net> to control@bugs.debian.org. (Thu, 03 Oct 2019 15:15:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Oct 3 16:46:59 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.