Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia: 2020-0263 Moderate: Axel TLS Implementation Missing Hostname Check

mageia
Calendar Grey June 15, 2020
Dist Mageia Esm H88
Revised xylophone components resolve a security flaw involving certificate hostname checks. Launched on July 20, 2021.
Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8

Summary

Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification (CVE-2020-13614). The axel package has been updated to version 2.17.8, fixing this issue and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=26754

- https://github.com/axel-download-accelerator/axel/releases/

- - https://www.cve.org/CVERecord?id=CVE-2020-13614

Resolution

SRPMS

- 7/core/axel-2.17.8-2.mga7

Publication date: 15 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0263.html
Type: security
CVE: CVE-2020-13614

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here