[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2019-8331 as no-dsa for stretch
Salvatore Bonaccorso
carnil at debian.org
Thu Feb 21 21:05:36 GMT 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4fb28c39 by Salvatore Bonaccorso at 2019-02-21T21:03:49Z
Mark CVE-2019-8331 as no-dsa for stretch
- - - - -
943dad27 by Salvatore Bonaccorso at 2019-02-21T21:05:11Z
Track proposed fix for twitter-bootstrap3 via stretch-pu
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1384,6 +1384,7 @@ CVE-2019-8332
CVE-2019-8331 (In Bootstrap before 4.3.1, XSS is possible in the tooltip or popover ...)
- twitter-bootstrap4 4.3.1+dfsg2-1
- twitter-bootstrap3 <unfixed>
+ [stretch] - twitter-bootstrap3 <no-dsa> (Minor issue)
- twitter-bootstrap <undetermined>
NOTE: https://github.com/twbs/bootstrap/pull/28236
CVE-2019-8330
=====================================
data/next-point-update.txt
=====================================
@@ -36,3 +36,5 @@ CVE-2018-9240
[stretch] - ncmpc 0.25-0.1+deb9u1
CVE-2018-1000035
[stretch] - unzip 6.0-21+deb9u1
+CVE-2019-8331
+ [stretch] - twitter-bootstrap3 3.3.7+dfsg-2+deb9u2
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/2efa75a6192c6020baeac3dbb63759542467d5d1...943dad27558b77205fa46c9cb8eee03133563133
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/2efa75a6192c6020baeac3dbb63759542467d5d1...943dad27558b77205fa46c9cb8eee03133563133
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190221/360e99c6/attachment.html>
More information about the debian-security-tracker-commits
mailing list