From bf60dc56f7247f977650d9861f35dd441f80c462 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Wed, 29 Jan 2020 09:35:06 +0100 Subject: Reference commits/patches for CVE-2020-7247/opensmtpd --- data/CVE/2020.list | 2 ++ 1 file changed, 2 insertions(+) diff --git a/data/CVE/2020.list b/data/CVE/2020.list index be3f95ee6d..bf1fae8508 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -2375,6 +2375,8 @@ CVE-2020-7247 [LPE and RCE in OpenSMTPD] RESERVED - opensmtpd 6.6.2p1-1 NOTE: https://www.openwall.com/lists/oss-security/2020/01/28/3 + NOTE: Fixed by: https://github.com/OpenSMTPD/OpenSMTPD/commit/2afab2297347342f81fa31a75bbbf7dbee614fda + NOTE: https://ftp.openbsd.org/pub/OpenBSD/patches/6.6/common/019_smtpd_exec.patch.sig CVE-2020-7246 (A remote code execution (RCE) vulnerability exists in qdPM 9.1 and ear ...) NOT-FOR-US: qdPM CVE-2020-7245 (Incorrect username validation in the registration process of CTFd v2.0 ...) -- cgit v1.2.3