[Git][security-tracker-team/security-tracker][master] freecol, okular spu
Moritz Muehlenhoff
jmm at debian.org
Sat Oct 10 12:12:21 BST 2020
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
59cd2e64 by Moritz Muehlenhoff at 2020-10-10T13:11:56+02:00
freecol, okular spu
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -41351,7 +41351,7 @@ CVE-2020-9360
CVE-2020-9359 (KDE Okular before 1.10.0 allows code execution via an action link in a ...)
{DLA-2159-1}
- okular 4:19.12.3-2 (bug #954891)
- [buster] - okular <no-dsa> (Minor issue)
+ [buster] - okular <no-dsa> (Minor issue, will be fixed via point update)
[stretch] - okular <no-dsa> (Minor issue)
NOTE: https://invent.kde.org/kde/okular/-/commit/6a93a033b4f9248b3cd4d04689b8391df754e244
NOTE: https://kde.org/info/security/advisory-20200312-1.txt
@@ -112659,7 +112659,7 @@ CVE-2018-1000826 (Microweber version <= 1.0.7 contains a Cross Site Scripting
NOT-FOR-US: Microweber
CVE-2018-1000825 (FreeCol version <= nightly-2018-08-22 contains a XML External Entit ...)
- freecol 0.11.6+dfsg2-3 (bug #917023; low)
- [buster] - freecol <no-dsa> (Minor issue)
+ [buster] - freecol <no-dsa> (Minor issue, will be fixed via spu)
[stretch] - freecol <no-dsa> (Minor issue)
[jessie] - freecol <end-of-life> (Games are not supported)
NOTE: https://github.com/FreeCol/freecol/issues/26
=====================================
data/next-point-update.txt
=====================================
@@ -32,3 +32,7 @@ CVE-2020-26117
[buster] - tigervnc 1.9.0+dfsg-3+deb10u3
CVE-2020-25073
[buster] - plinth 19.1+deb10u1
+CVE-2020-9359
+ [buster] - okular 4:17.12.2-2.2+deb10u1
+CVE-2018-1000825
+ [buster] - freecol 0.11.6+dfsg2-2+deb10u1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59cd2e64f0157e09bbf90d6e813b03265c6ee40e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59cd2e64f0157e09bbf90d6e813b03265c6ee40e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201010/57b47561/attachment.html>
More information about the debian-security-tracker-commits
mailing list