[Pkg-javascript-devel] Bug#992292: Bugs #992290 #992291 #992292 : ckeditor: CVE-2021-37695 CVE-2021-32808 CVE-2021-32809

Yadd yadd at debian.org
Wed Aug 18 07:30:44 BST 2021


Le 16/08/2021 à 21:55, Salvatore Bonaccorso a écrit :
> Source: ckeditor
> Version: 4.16.0+dfsg-2
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
> Control: found -1 4.11.1+dfsg-1
> 
> Hi,
> 
> The following vulnerability was published for ckeditor.

Backporting these 3 CVE fixes in Bullseye produces a big patch (~2000
lines) and I'm not sure to be able to backport this without including
ckeditor 4.16.1 changes.

For now, "too-intrusive"...



More information about the Pkg-javascript-devel mailing list