Abhijith PA pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7e441e86 by Abhijith PA at 2020-10-20T22:57:34+05:30
Seems it is not reproducible with PoC 
https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
Marked as not-affected fot stretch

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32416,6 +32416,7 @@ CVE-2020-12649 (Gurbalib through 2020-04-30 allows 
lib/cmds/player/help.c direct
 CVE-2020-12648 (A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 
and earlie ...)
        - tinymce <unfixed>
        [buster] - tinymce <no-dsa> (Minor issue)
+       [stretch] - tinymce <not-affected> (Vulnerable code not present and not 
reproducible)
        NOTE: https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
 CVE-2020-12647 (Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 
59.1a.9, and 6 ...)
        NOT-FOR-US: Unisys ALGOL Compiler



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e441e8685819e967648059f620b871014a09929

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e441e8685819e967648059f620b871014a09929
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to