Debian Csync2 vulnerabilities
2 known vulnerabilities affecting debian/csync2.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-15522CRITICALCVSS 9.8fixed in csync2 2.0-25-gc0faaf9-1 (bookworm)2019
CVE-2019-15522 [CRITICAL] CVE-2019-15522: csync2 - An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in da...
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
Scope: local
bookworm: resolved (fixed in 2.0-25-gc0faaf9-1)
bullseye: resolved (fixed in 2.0-25-gc0faaf9-1)
forky: resolved (fixed in 2.0-25-gc0faaf9-1)
sid: resolved (fixed in 2.0-25-gc
debian
CVE-2019-15523MEDIUMCVSS 5.3fixed in csync2 2.0-25-gc0faaf9-1 (bookworm)2019
CVE-2019-15523 [MEDIUM] CVE-2019-15523: csync2 - An issue was discovered in LINBIT csync2 through 2.0. It does not correctly chec...
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
Scope: local
bookworm: resolved (fixed in 2.0-25-gc0faaf9-1)
bullseye: resolved (fixed in 2.0-25-gc0faaf9-1)
forky: r
debian