[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2178-1] awl security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : awl
Version        : 0.55-1+deb8u1
CVE ID         : CVE-2020-11728 CVE-2020-11729
Debian Bug     : 956650


Following CVEs were reported against the awl source package:

CVE-2020-11728

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL)
    through 0.60. Session management does not use a sufficiently
    hard-to-guess session key. Anyone who can guess the microsecond
    time (and the incrementing session_id) can impersonate a session.

CVE-2020-11729

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL)
    through 0.60. Long-term session cookies, uses to provide
    long-term session continuity, are not generated securely, enabling
    a brute-force attack that may be successful.

For Debian 8 "Jessie", these problems have been fixed in version
0.55-1+deb8u1.

We recommend that you upgrade your awl packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Best,
Utkarsh
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl6aQEIACgkQgj6WdgbD
S5YfLQ/9Ho2jvcWYqOqrTOJD+3fpujeM1L44GUFJ/nvpACimLrPqOfNVP5VjXDiY
cy+NFaSmX8trJRqhcRO6Q3DEg0hp0qxxY3LTrrrFdyN586k9lp8bWz0k9pnIVE5z
H7jMUTpyhO108hxtlWYF1x/uRebMJ0JpMEkiudUOzKFUnsfxoT544gnoif74BtZv
27yw2iQJVWe8H9ZfYGs24RLVeBv7lUGtclW3pA6R10iJalovCXogWvzr0o5kulK7
LU34V4tbZ0X94Npt/KKdRhJtF2v0+wNt0nK0SNnV2mZg5TpEpq2lECORA1YMa7mp
tSrSgAV2ynkAYmAwABamyzSEHbj1Nph0wtb8AtPYLz69THJurkw/3Bal0CPagOPC
6LAc+biRf6e7AMmsfGbqGFLEvcUZUZvU00olpEeR5S53Ss2wq2DIED7N5W+IhwjR
37El5r4Dc0PlYcp8U9qJO5OsfFGhyLjaEsHmF5IkpoWf6Vz3LrD/IgZDlFJfWHXi
XGHeElE0zMjMDsAJ8OUNkvfOnKYdXCKq8xUEeQBzfVl7n5Kc9dIFnNzGerFJ24iv
T29rRKm1ibktjrG16Y6u4b+Uonwh9wF/tcJWBOICrJdUDWWgNMphaY3GeLzhpq6+
uB/ElQSxDejOhXyIXr2equdqTWjWP/LqXvqQllkZhxKDWxGMjCo=
=d8w5
-----END PGP SIGNATURE-----


Reply to: