Bugzilla – Bug 1147139
VUL-1: CVE-2019-15523: csync2: incorrect TLS handshake error handling
Last modified: 2024-07-26 21:00:14 UTC
> An issue was discovered in LINBIT csync2 through 2.0. > The client and daemon do not correctly check for > the return value GNUTLS_E_WARNING_ALERT_RECEIVED of gnutls_handshake(). > They neglect to call the function multiple times in order to retrieve > all return values, potentially allowing remote attackers to create TLS > connections with unhandled validation or connection issues. > suggested patch: https://github.com/LINBIT/csync2/pull/13/commits/92742544a56bcbcd9ec99ca15f898b31797e39e2
Tracked as affected SLE12 and SLE15
This is an autogenerated message for OBS integration: This bug (1147139) was mentioned in https://build.opensuse.org/request/show/883676 Factory / csync2
This is an autogenerated message for OBS integration: This bug (1147139) was mentioned in https://build.opensuse.org/request/show/883785 Factory / csync2
SUSE-SU-2021:1858-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1147137,1147139 CVE References: CVE-2019-15522,CVE-2019-15523 JIRA References: Sources used: SUSE Linux Enterprise High Availability 15-SP2 (src): csync2-2.0+git.1461714863.10636a4-4.6.1 SUSE Linux Enterprise High Availability 15-SP1 (src): csync2-2.0+git.1461714863.10636a4-4.6.1 SUSE Linux Enterprise High Availability 15 (src): csync2-2.0+git.1461714863.10636a4-4.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:0853-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1147137,1147139 CVE References: CVE-2019-15522,CVE-2019-15523 JIRA References: Sources used: openSUSE Leap 15.2 (src): csync2-2.0+git.1461714863.10636a4-lp152.5.3.1
SUSE-SU-2021:1952-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1147137,1147139 CVE References: CVE-2019-15522,CVE-2019-15523 JIRA References: Sources used: SUSE Linux Enterprise High Availability 12-SP5 (src): csync2-2.0+git.1368794815.cf835a7-3.9.5 SUSE Linux Enterprise High Availability 12-SP4 (src): csync2-2.0+git.1368794815.cf835a7-3.9.5 SUSE Linux Enterprise High Availability 12-SP3 (src): csync2-2.0+git.1368794815.cf835a7-3.9.5 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.