[Git][security-tracker-team/security-tracker][master] Triaged libsass a bit, but it's just the tip of the iceberg, should not

Moritz Muehlenhoff jmm at debian.org
Sun Feb 10 13:49:07 GMT 2019


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4a961fce by Moritz Muehlenhoff at 2019-02-10T13:48:11Z
Triaged libsass a bit, but it's just the tip of the iceberg, should not
be included in buster unless it improves

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -40115,13 +40115,15 @@ CVE-2018-11698 (An issue was discovered in LibSass through 3.5.4. An out-of-boun
 	[stretch] - libsass <no-dsa> (Minor issue)
 	NOTE: https://github.com/sass/libsass/issues/2662
 CVE-2018-11697 (An issue was discovered in LibSass through 3.5.4. An out-of-bounds read ...)
-	- libsass <unfixed>
+	- libsass 3.5.4+20180621~c0a6cf3-1
 	[stretch] - libsass <no-dsa> (Minor issue)
 	NOTE: https://github.com/sass/libsass/issues/2656
+	NOTE: https://github.com/xzyfer/libsass/commit/024bb12511ce43fae8bb3737558f5cfe37a38a59
 CVE-2018-11696 (An issue was discovered in LibSass through 3.5.4. A NULL pointer ...)
-	- libsass <unfixed>
+	- libsass 3.5.4+20180621~c0a6cf3-1
 	[stretch] - libsass <no-dsa> (Minor issue)
 	NOTE: https://github.com/sass/libsass/issues/2665
+	NOTE: https://github.com/xzyfer/libsass/commit/0768c4a20fa3075d3b879c334f3fade13a763b08
 CVE-2018-11695 (An issue was discovered in LibSass through 3.5.2. A NULL pointer ...)
 	- libsass <unfixed>
 	[stretch] - libsass <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/4a961fce792554c6c01fc030777fcb633b46481e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/4a961fce792554c6c01fc030777fcb633b46481e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190210/9d8ca514/attachment.html>


More information about the debian-security-tracker-commits mailing list