[Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2019-19919/node-handlebars as no-dsa

Salvatore Bonaccorso carnil at debian.org
Mon Dec 30 11:01:52 GMT 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
68658915 by Salvatore Bonaccorso at 2019-12-30T11:00:01Z
Mark CVE-2019-19919/node-handlebars as no-dsa

- - - - -
d6be9048 by Salvatore Bonaccorso at 2019-12-30T11:00:40Z
Track fixed version for CVE-2019-19919/node-handlebars via unstable

- - - - -
606bb522 by Salvatore Bonaccorso at 2019-12-30T11:01:28Z
Track proposed update for node-handlebars via buster-pu

- - - - -


2 changed files:

- data/CVE/list
- data/next-point-update.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -433,7 +433,8 @@ CVE-2019-19922 (kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.c
 CVE-2019-19921
 	RESERVED
 CVE-2019-19919 (Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Poll ...)
-	- node-handlebars <unfixed>
+	- node-handlebars 3:4.5.3-1
+	[buster] - node-handlebars <no-dsa> (Minor issue; will be fixed via point release)
 	NOTE: https://www.npmjs.com/advisories/1164
 CVE-2019-19918 (Lout 3.40 has a heap-based buffer overflow in the srcnext() function i ...)
 	- lout <unfixed> (bug #947113)


=====================================
data/next-point-update.txt
=====================================
@@ -81,6 +81,8 @@ CVE-2019-15680
        [buster] - tightvnc 1:1.3.9-9deb10u1
 CVE-2019-15681
        [buster] - tightvnc 1:1.3.9-9deb10u1
+CVE-2019-19919
+	[buster] - node-handlebars 3:4.1.0-1+deb10u1
 CVE-2019-14814
 	[buster] - linux 4.19.87-1
 CVE-2019-14815



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/eeb3197c3b0b405318ca720483b7f39b481293a2...606bb522e7dec71506f7680d275a3dfe481d9b92

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/eeb3197c3b0b405318ca720483b7f39b481293a2...606bb522e7dec71506f7680d275a3dfe481d9b92
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191230/85a1dd07/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list