FreeBSD Bugzilla – Attachment 249492 Details for
Bug 277692
net/quiche: update to 0.20.1 (fixes 2 CVE's)
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
Add entry to VuXML for quiche
vuln_2024.xml (text/plain), 1.42 KB, created by
Ralf van der Enden
on 2024-03-26 10:22:57 UTC
(
hide
)
Description:
Add entry to VuXML for quiche
Filename:
MIME Type:
Creator:
Ralf van der Enden
Created:
2024-03-26 10:22:57 UTC
Size:
1.42 KB
patch
obsolete
>diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml >index 7b227fba72..e5cc24bb53 100644 >--- a/security/vuxml/vuln/2024.xml >+++ b/security/vuxml/vuln/2024.xml >@@ -1,3 +1,34 @@ >+ <vuln vid="34f98d06-eb56-11ee-8007-6805ca2fa271"> >+ <topic>quiche -- Multiple Vulnerabilities</topic> >+ <affects> >+ <package> >+ <name>quiche</name> >+ <range><lt>0.20.1</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Quiche Releases reports:</p> >+ <blockquote cite="https://github.com/cloudflare/quiche/releases/tag/0.20.1"> >+ <p>This release includes 2 security fixes:</p> >+ <ul> >+ <li>CVE-2024-1410: Unbounded storage of information related to connection ID retirement, in quiche. Reported by Marten Seeman (@marten-seeman)</li> >+ <li>CVE-2024-1765: Unlimited resource allocation by QUIC CRYPTO frames flooding in quiche. Reported by Marten Seeman (@marten-seeman)</li> >+ </ul> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2024-1410</cvename> >+ <cvename>CVE-2024-1765</cvename> >+ <url>https://github.com/cloudflare/quiche/releases/tag/0.20.1</url> >+ </references> >+ <dates> >+ <discovery>2024-03-12</discovery> >+ <entry>2024-03-26</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="80815c47-e84f-11ee-8e76-a8a1599412c6"> > <topic>chromium -- multiple security fixes</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 277692
:
249158
| 249492