Ola Lundqvist pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4176e72c by Ola Lundqvist at 2020-02-27T22:57:55+01:00
Changed python-bleach CVE from not-affected to ignored. Salvatore pointed out
that it was a wrong conclusion but the fix is too invasive in jessie.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -217,7 +217,8 @@ CVE-2020-9336 (fauzantrif eLection 2.0 has XSS via the
Admin Dashboard -> Set
CVE-2020-6802 [mutation XSS vulnerability]
RESERVED
- python-bleach 3.1.1-1 (bug #951907)
- [jessie] - python-bleach <not-affected> (Vulnerable functionality does
not exist in this version)
+ [jessie] - python-bleach <ignored> (Fix too invasive in jessie)
+ NOTE: Jessie version uses an external html5 parser making a fix
invasive.
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1615315 (not public)
NOTE:
https://github.com/mozilla/bleach/security/advisories/GHSA-q65m-pv3f-wr5r
NOTE:
https://github.com/mozilla/bleach/commit/f77e0f6392177a06e46a49abd61a4d9f035e57fd
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4176e72ce831b572f2dca8f56dbd1fd90b8dd655
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4176e72ce831b572f2dca8f56dbd1fd90b8dd655
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits