[Git][security-tracker-team/security-tracker][master] Correct source package name for CVE-2019-10747
Salvatore Bonaccorso
carnil at debian.org
Thu Sep 26 14:59:06 BST 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c50f91da by Salvatore Bonaccorso at 2019-09-26T13:58:38Z
Correct source package name for CVE-2019-10747
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18257,8 +18257,8 @@ CVE-2019-10748
RESERVED
CVE-2019-10747 (set-value is vulnerable to Prototype Pollution in versions lower than ...)
- node-set-value <unfixed> (bug #941189)
- [buster] - node-mixin-deep <no-dsa> (Minor issue, will be fixed via point release)
- [stretch] - node-mixin-deep <ignored> (Nodejs in stretch not covered by security support)
+ [buster] - node-set-value <no-dsa> (Minor issue, will be fixed via point release)
+ [stretch] - node-set-value <ignored> (Nodejs in stretch not covered by security support)
NOTE: https://snyk.io/vuln/SNYK-JS-SETVALUE-450213
CVE-2019-10746 (mixin-deep is vulnerable to Prototype Pollution in versions before 1.3 ...)
- node-mixin-deep 2.0.1-1 (bug #932500)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/c50f91da02ca2335e1df0556a19309861e17ea70
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/c50f91da02ca2335e1df0556a19309861e17ea70
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190926/162bdb1c/attachment.html>
More information about the debian-security-tracker-commits
mailing list