[Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2018-1000652/jabref
Salvatore Bonaccorso
carnil at debian.org
Sat Feb 9 20:48:23 GMT 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eafe8294 by Salvatore Bonaccorso at 2019-02-09T20:47:45Z
Add fixed version via unstable for CVE-2018-1000652/jabref
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -29917,7 +29917,7 @@ CVE-2018-1000654 (GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn
CVE-2018-1000653 (zzcms version 8.3 and earlier contains a SQL Injection vulnerability ...)
NOT-FOR-US: zzcms
CVE-2018-1000652 (JabRef version <=4.3.1 contains a XML External Entity (XXE) ...)
- - jabref <unfixed> (low; bug #921772)
+ - jabref 3.8.2+ds-12 (low; bug #921772)
[stretch] - jabref <no-dsa> (Minor issue)
[jessie] - jabref <no-dsa> (Minor issue)
NOTE: https://github.com/JabRef/jabref/issues/4229
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/eafe82944a8b898e3ecc9fa77dc3e35986b2a70d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/eafe82944a8b898e3ecc9fa77dc3e35986b2a70d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190209/a94a8e71/attachment.html>
More information about the debian-security-tracker-commits
mailing list