From 1b992dbd51860b85ec6417d5afea716a0cad2522 Mon Sep 17 00:00:00 2001 From: Anton Gladky Date: Sat, 6 Mar 2021 19:03:28 +0100 Subject: Add information about CVE-2020-11997 --- data/CVE/2020.list | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/data/CVE/2020.list b/data/CVE/2020.list index 47b60b4af0..97a77dff92 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -42556,9 +42556,12 @@ CVE-2020-11998 (A regression has been introduced in the commit preventing JMX re - activemq (Only affects 5.15.12) NOTE: http://activemq.apache.org/security-advisories.data/CVE-2020-11998-announcement.txt CVE-2020-11997 (Apache Guacamole 1.2.0 and earlier do not consistently restrict access ...) - - guacamole-server 1.3.0-1 + NOT-FOR-US: ancient versions in the archive NOTE: https://lists.apache.org/thread.html/r1a9ae9d1608c9f846875c4191cd738f95543d1be06b52dc1320e8117%40%3Cannounce.guacamole.apache.org%3E TODO: check details, both guacamole-client and guacamole-server affected? + NOTE: according to upstream only guacamole-client is affected. The fix for the + NOTE: very ancient version in archive (0.8.3-1.1 - stretch, 0.9.9+dfsg-1 - sid) + NOTE: is very complicated (almost impossible). CVE-2020-11996 (A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat ...) {DSA-4727-1 DLA-2279-1} - tomcat9 9.0.36-1 -- cgit v1.2.3