[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2019-8331 as no-dsa for stretch

Salvatore Bonaccorso carnil at debian.org
Thu Feb 21 21:05:36 GMT 2019


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4fb28c39 by Salvatore Bonaccorso at 2019-02-21T21:03:49Z
Mark CVE-2019-8331 as no-dsa for stretch

- - - - -
943dad27 by Salvatore Bonaccorso at 2019-02-21T21:05:11Z
Track proposed fix for twitter-bootstrap3 via stretch-pu

- - - - -


2 changed files:

- data/CVE/list
- data/next-point-update.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1384,6 +1384,7 @@ CVE-2019-8332
 CVE-2019-8331 (In Bootstrap before 4.3.1, XSS is possible in the tooltip or popover ...)
 	- twitter-bootstrap4 4.3.1+dfsg2-1
 	- twitter-bootstrap3 <unfixed>
+	[stretch] - twitter-bootstrap3 <no-dsa> (Minor issue)
 	- twitter-bootstrap <undetermined>
 	NOTE: https://github.com/twbs/bootstrap/pull/28236
 CVE-2019-8330


=====================================
data/next-point-update.txt
=====================================
@@ -36,3 +36,5 @@ CVE-2018-9240
 	[stretch] - ncmpc 0.25-0.1+deb9u1
 CVE-2018-1000035
 	[stretch] - unzip 6.0-21+deb9u1
+CVE-2019-8331
+	[stretch] - twitter-bootstrap3 3.3.7+dfsg-2+deb9u2



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/2efa75a6192c6020baeac3dbb63759542467d5d1...943dad27558b77205fa46c9cb8eee03133563133

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/2efa75a6192c6020baeac3dbb63759542467d5d1...943dad27558b77205fa46c9cb8eee03133563133
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190221/360e99c6/attachment.html>


More information about the debian-security-tracker-commits mailing list