Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ec8bca1e by Salvatore Bonaccorso at 2020-05-26T19:43:18+02:00
Associate CVE-2018-18405 with jquery but mark it as unimporant

The validity of the CVE is unclear anyway and several third parties have
raised the issue as beeing just a spam entry.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -94024,7 +94024,7 @@ CVE-2018-18407 (A heap-based buffer over-read was 
discovered in the tcpreplay-ed
 CVE-2018-18406 (An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 
2.16 bu ...)
        NOT-FOR-US: Tufin SecureTrack
 CVE-2018-18405 (jQuery v2.2.2 allows XSS via a crafted onerror attribute of an 
IMG ele ...)
-       TODO: to be checked, unclear validity of the CVE
+       - jquery <removed> (unimportant)
 CVE-2018-18404
        RESERVED
 CVE-2018-18403



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec8bca1e5dfe03181ca28ac0b2700407ffbaca5e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec8bca1e5dfe03181ca28ac0b2700407ffbaca5e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to