Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id B0944200C67 for ; Mon, 15 May 2017 15:43:20 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id AF229160BD0; Mon, 15 May 2017 13:43:20 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id CCD2B160BC1 for ; Mon, 15 May 2017 15:43:19 +0200 (CEST) Received: (qmail 32841 invoked by uid 500); 15 May 2017 13:43:19 -0000 Mailing-List: contact commits-help@qpid.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@qpid.apache.org Delivered-To: mailing list commits@qpid.apache.org Received: (qmail 32825 invoked by uid 99); 15 May 2017 13:43:18 -0000 Received: from git1-us-west.apache.org (HELO git1-us-west.apache.org) (140.211.11.23) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 15 May 2017 13:43:18 +0000 Received: by git1-us-west.apache.org (ASF Mail Server at git1-us-west.apache.org, from userid 33) id BA129E0016; Mon, 15 May 2017 13:43:18 +0000 (UTC) Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: jross@apache.org To: commits@qpid.apache.org Date: Mon, 15 May 2017 13:43:18 -0000 Message-Id: <45713d9f789c4fa3bd5d8324ba68bb4b@git.apache.org> X-Mailer: ASF-Git Admin Mailer Subject: [1/3] qpid-site git commit: QPID-7756: Give each CVE its own page; link to CVEs from component pages archived-at: Mon, 15 May 2017 13:43:20 -0000 Repository: qpid-site Updated Branches: refs/heads/asf-site d03960c7e -> 891f697bd http://git-wip-us.apache.org/repos/asf/qpid-site/blob/891f697b/input/proton/security.md ---------------------------------------------------------------------- diff --git a/input/proton/security.md b/input/proton/security.md index f708f56..e793119 100644 --- a/input/proton/security.md +++ b/input/proton/security.md @@ -19,120 +19,10 @@ # Security -
+| CVE-ID | Severity | Affected versions | Fixed versions | Summary | +| ------ | -------- | ----------------- | -------------- | ------- | +| [CVE-2016-4467]({{site_url}}/cves/CVE-2016-4467.html) | Medium | 0.8 through 0.13.0 inclusive | 0.13.1 and later | Failure to verify that the server host name matches the certificate host name on Windows | +| [CVE-2016-2166]({{site_url}}/cves/CVE-2016-2166.html) | Moderate | 0.9 through 0.12.0 inclusive | 0.12.1 and later | Python bindings silently ignore request for amqps if SSL/TLS not supported | -## Proton - - - - - - - - - - - - - - - - - - - - - - - -
CVE-IDSeverityAffected VersionsFixed in VersionsDescription
CVE-2016-4467Medium0.8 through 0.13.0 (inclusive)0.13.1 and laterFailure to verify that the server host name matches the certificate host name on Windows - show more - -
CVE-2016-2166Moderate0.9 through 0.12.0 (inclusive)0.12.1 and later - Python bindings silently ignore request for amqps if SSL/TLS not supported. show more - -
- -
- -See the main [Security]({{site_url}}/security.html) page for general information and details for other components. +See the main [Security]({{site_url}}/security.html) page for general +information and details for other components. http://git-wip-us.apache.org/repos/asf/qpid-site/blob/891f697b/input/security.md ---------------------------------------------------------------------- diff --git a/input/security.md b/input/security.md index 4361ac2..85eaa96 100644 --- a/input/security.md +++ b/input/security.md @@ -21,7 +21,7 @@
-## Security Updates +## Security updates Details of security problems fixed in released versions of individual Apache Qpid components are detailed at: @@ -30,13 +30,12 @@ Qpid components are detailed at:
- [Broker for Java]({{site_url}}/components/java-broker/security.html) - - [C++ Broker]({{site_url}}/components/cpp-broker/security.html) + - [C++ broker]({{site_url}}/components/cpp-broker/security.html)
- - [JMS Client (AMQP 1.0)]({{site_url}}/components/jms/security.html) - - [JMS Client (AMQP 0.x)]({{site_url}}/components/jms/security-0-x.html) + - [JMS client]({{site_url}}/components/jms/security.html) - [Proton]({{site_url}}/proton/security.html)
@@ -45,7 +44,7 @@ Qpid components are detailed at:
-## Reporting New Security Problems with Apache Qpid +## Reporting new security problems with Apache Qpid We take a very active stance in eliminating security problems and denial of service attacks against Apache Qpid. --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscribe@qpid.apache.org For additional commands, e-mail: commits-help@qpid.apache.org