Bug 1829206 (CVE-2019-15522) - CVE-2019-15522 csync2: csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL
Summary: CVE-2019-15522 csync2: csync_daemon_session in daemon.c neglects to force a f...
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2019-15522
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1829207 1829208
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-04-29 08:25 UTC by Marian Rehak
Modified: 2020-04-29 10:31 UTC (History)
4 users (show)

Fixed In Version: csync2 2.0
Clone Of:
Environment:
Last Closed: 2020-04-29 10:31:46 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2020-04-29 08:25:22 UTC
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.

Upstream commit:

https://github.com/LINBIT/csync2/pull/13/commits/0ecfc333da51575f188dd7cf6ac4974d13a800b1

Comment 1 Marian Rehak 2020-04-29 08:25:55 UTC
Created csync2 tracking bugs for this issue:

Affects: epel-6 [bug 1829208]
Affects: fedora-all [bug 1829207]

Comment 2 Product Security DevOps Team 2020-04-29 10:31:46 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.