[CLSA-2023:1689701258] Fix CVE(s): CVE-2021-20230
Type:
security
Severity:
Important
Release date:
2023-07-18 17:27:43 UTC
Description:
* SECURITY UPDATE: Attacker bypasses redirection using unauthorized CA-signed certificate. - debian/patches/CVE-2021-20230.patch: Patch enhancing certificate verification process to prevent unauthorized redirection with CA-signed certificates by refining session data checks. - CVE-2021-20230 * Fix tests: - debian/patches/renew-cert-script.patch: Add script that re-generate expired test certs. * Repacked orig source tarball with renewed certs. * Removed no longer required patch, that mute tests with expired certificates.
Updated packages:
  • stunnel4_5.44-1ubuntu3+tuxcare.els1_amd64.deb
    sha:aa61e76ee1bd7e8d1012093f3e28e4a076c76a48
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.