CVE-2019-15523
published 2020-12-30CVE-2019-15523: An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.32%
68.1th percentile
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | csync2 | < csync2 2.0-25-gc0faaf9-1 (bookworm) | csync2 2.0-25-gc0faaf9-1 (bookworm) |
| debian | debian_linux | — | — |
| linbit | csync2 | <= 2.0 | — |
| linbit | csync2 | >= 0 < 2.0-25-gc0faaf9-1 | 2.0-25-gc0faaf9-1 |
| linbit | csync2 | >= 0 < 2.0-25-gc0faaf9-1 | 2.0-25-gc0faaf9-1 |
| linbit | csync2 | >= 0 < 2.0-25-gc0faaf9-1 | 2.0-25-gc0faaf9-1 |
| linbit | csync2 | >= 0 < 2.0-25-gc0faaf9-1 | 2.0-25-gc0faaf9-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hw3p-w63h-mj9c: An issue was discovered in LINBIT csync2 through 2
ghsa_unreviewed·2022-05-24
CVE-2019-15523 [MEDIUM] CWE-252 GHSA-hw3p-w63h-mj9c: An issue was discovered in LINBIT csync2 through 2
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
OSV
CVE-2019-15523: An issue was discovered in LINBIT csync2 through 2
osv·2020-12-30·CVSS 5.3
CVE-2019-15523 [MEDIUM] CVE-2019-15523: An issue was discovered in LINBIT csync2 through 2
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
Debian
CVE-2019-15523: csync2 - An issue was discovered in LINBIT csync2 through 2.0. It does not correctly chec...
vendor_debian·2019·CVSS 5.3
CVE-2019-15523 [MEDIUM] CVE-2019-15523: csync2 - An issue was discovered in LINBIT csync2 through 2.0. It does not correctly chec...
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
Scope: local
bookworm: resolved (fixed in 2.0-25-gc0faaf9-1)
bullseye: resolved (fixed in 2.0-25-gc0faaf9-1)
forky: resolved (fixed in 2.0-25-gc0faaf9-1)
sid: resolved (fixed in 2.0-25-gc0faaf9-1)
trixie: resolved (fixed in 2.0-25-gc0faaf9-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LINBIT/csync2/pull/13/commits/92742544a56bcbcd9ec99ca15f898b31797e39e2https://lists.debian.org/debian-lts-announce/2021/01/msg00003.htmlhttps://github.com/LINBIT/csync2/pull/13/commits/92742544a56bcbcd9ec99ca15f898b31797e39e2https://lists.debian.org/debian-lts-announce/2021/01/msg00003.html
2020-12-30
Published