[Secure-testing-commits] r37519 - in data: . CVE
Raphaël Hertzog
hertzog at moszumanska.debian.org
Tue Nov 3 09:39:17 UTC 2015
Author: hertzog
Date: 2015-11-03 09:39:15 +0000 (Tue, 03 Nov 2015)
New Revision: 37519
Modified:
data/CVE/list
data/dla-needed.txt
Log:
Add libhtml-scrubber-perl to dla-needed.txt
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-11-03 06:07:33 UTC (rev 37518)
+++ data/CVE/list 2015-11-03 09:39:15 UTC (rev 37519)
@@ -5917,6 +5917,7 @@
TODO: check
CVE-2015-5667 (Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module ...)
- libhtml-scrubber-perl 0.15-1
+ NOTE: Upstream fix: https://github.com/nigelm/html-scrubber/commit/e1978cc37867e85c06a84a4651745235010cd6cd
CVE-2015-5666
RESERVED
CVE-2015-5665 (Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE ...)
Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt 2015-11-03 06:07:33 UTC (rev 37518)
+++ data/dla-needed.txt 2015-11-03 09:39:15 UTC (rev 37519)
@@ -18,6 +18,8 @@
--
krb5 (Guido Günther)
--
+libhtml-scrubber-perl
+--
libphp-snoopy
--
libvncserver (Mike Gabriel)
More information about the Secure-testing-commits
mailing list