FreeBSD Bugzilla – Attachment 227608 Details for
Bug 258187
net-im/py-matrix-synapse: Update to 1.41.1
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
security/vuxml diff
vuxml.diff (text/plain), 1.61 KB, created by
Ashish SHUKLA
on 2021-09-02 14:22:47 UTC
(
hide
)
Description:
security/vuxml diff
Filename:
MIME Type:
Creator:
Ashish SHUKLA
Created:
2021-09-02 14:22:47 UTC
Size:
1.61 KB
patch
obsolete
>diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml >index 2b73958..31ce37c 100644 >--- a/security/vuxml/vuln-2021.xml >+++ b/security/vuxml/vuln-2021.xml >@@ -1,3 +1,42 @@ >+ <vuln vid="a67e358c-0bf6-11ec-875e-901b0e9408dc"> >+ <topic>py-matrix-synapse -- several vulnerabilities</topic> >+ <affects> >+ <package> >+ <name>py36-matrix-synapse</name> >+ <name>py37-matrix-synapse</name> >+ <name>py38-matrix-synapse</name> >+ <name>py39-matrix-synapse</name> >+ <name>py310-matrix-synapse</name> >+ <range><lt>1.41.1</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Matrix developers report:</p> >+ <blockquote cite="https://matrix.org/blog/2021/08/31/synapse-1-41-1-released"> >+ <p>This release patches two moderate severity issues which >+ could reveal metadata about private rooms:</p> >+ <ul> >+ <li>CVE-2021-39164: Enumerating a private room's list of >+ members and their display names.</li> >+ <li>CVE-2021-39163: Disclosing a private room's name, >+ avatar, topic, and number of members.</li> >+ </ul> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <freebsdpr>ports/258187</freebsdpr> >+ <cvename>CVE-2021-39164</cvename> >+ <cvename>CVE-2021-39163</cvename> >+ <url>https://matrix.org/blog/2021/08/31/synapse-1-41-1-released</url> >+ </references> >+ <dates> >+ <discovery>2021-08-31</discovery> >+ <entry>2021-09-02</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="032643d7-0ba7-11ec-a689-080027e50e6d"> > <topic>Python -- multiple vulnerabilities</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 258187
:
227574
| 227608