[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2018-1000652/jabref
Salvatore Bonaccorso
carnil at debian.org
Sat Feb 9 04:08:43 GMT 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7f0a2904 by Salvatore Bonaccorso at 2019-02-09T04:08:14Z
Add Debian bug reference for CVE-2018-1000652/jabref
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -29828,7 +29828,7 @@ CVE-2018-1000654 (GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn
CVE-2018-1000653 (zzcms version 8.3 and earlier contains a SQL Injection vulnerability ...)
NOT-FOR-US: zzcms
CVE-2018-1000652 (JabRef version <=4.3.1 contains a XML External Entity (XXE) ...)
- - jabref <unfixed> (low)
+ - jabref <unfixed> (low; bug #921772)
[stretch] - jabref <no-dsa> (Minor issue)
[jessie] - jabref <no-dsa> (Minor issue)
NOTE: https://github.com/JabRef/jabref/issues/4229
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/7f0a2904bd36d4884529940864658082ed1136e6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/7f0a2904bd36d4884529940864658082ed1136e6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190209/47bde911/attachment.html>
More information about the debian-security-tracker-commits
mailing list