OESA-2021-1037

    Dashboard / Vulnerabilities / OESA-2021-1037

    OESA-2021-1037

    Published: 10 Feb 2021Last Modified: 18 Aug 2026
    Upstream:

    Summary: gssproxy security update

    Details: This is a proxy for GSSAPI which deals with credential handling.\r\n\r\n Security Fix(es):\r\n\r\n ** DISPUTED ** gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem."(CVE-2020-12658)\r\n\r\n

    Affected packages

    Package

    Name: gssproxy

    Purl: pkg:rpm/openEuler/gssproxy&distro=openEuler-20.03-LTS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.8.3-1.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2021-1037 | CVE-DB