GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Dec 23, 2020 8:26 pm Post subject: [ GLSA 202012-09 ] Cherokee |
|
|
Gentoo Linux Security Advisory
Title: Cherokee: Multiple vulnerabilities (GLSA 202012-09)
Severity: low
Exploitable: remote
Date: 2020-12-23
Bug(s): #715204
ID: 202012-09
Synopsis
Multiple vulnerabilities have been found in Cherokee, the worst of
which could result in a Denial of Service condition.
Background
Cherokee is an extra-light web server.
Affected Packages
Package: www-servers/cherokee
Vulnerable: <= 1.2.104-r2
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Cherokee. Please review
the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
Gentoo has discontinued support for Cherokee. We recommend that users
unmerge package:
Code: | # emerge --unmerge "www-servers/cherokee"
|
References
CVE-2006-1681
CVE-2019-20798
CVE-2019-20799
CVE-2019-20800
CVE-2020-12845 |
|