VYPR

rpm package

opensuse/notary&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/notary&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2019-17596Oct 24, 2019
    affected < 0.7.0-1.2fixed 0.7.0-1.2

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2019-9512Aug 13, 2019
    affected < 0.7.0-1.2fixed 0.7.0-1.2

    Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consum