Debian Bug report logs -
#941667
osc: CVE-2019-3685
Reply or subscribe to this bug.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, team@security.debian.org, RPM packaging team <team+pkg-rpm@tracker.debian.org>
:
Bug#941667
; Package osc
.
(Thu, 03 Oct 2019 14:54:05 GMT) (full text, mbox, link).
Acknowledgement sent
to Sylvain Beucler <beuc@beuc.net>
:
New Bug report received and forwarded. Copy sent to team@security.debian.org, RPM packaging team <team+pkg-rpm@tracker.debian.org>
.
(Thu, 03 Oct 2019 14:54:05 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: osc
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security
Hi,
The following vulnerability was published for osc.
CVE-2019-3685[0]:
Fails to adequately verify TLS certificates allowing for a man in the middle attack
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
Sadly, little information is known at the moment:
[0] https://security-tracker.debian.org/tracker/CVE-2019-3685
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3685
https://bugzilla.redhat.com/show_bug.cgi?id=1737797
To the least, it would help to know which versions are affected.
Please adjust the affected versions in the BTS as needed.
Cheers!
Sylvain Beucler
Debian LTS Team
Changed Bug title to 'osc: CVE-2019-3685' from 'CVE-2019-3685'.
Request was from Sylvain Beucler <beuc@beuc.net>
to control@bugs.debian.org
.
(Thu, 03 Oct 2019 15:15:03 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Thu Oct 3 16:46:59 2019;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.