Accepted php5 5.4.45-0+deb7u12 (source amd64 all) into oldoldstable

2018-01-20 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2018 14:25:57 +0100 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp

[SECURITY] [DLA 1251-1] php5 security update

2018-01-20 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: php5 Version: 5.4.45-0+deb7u12 CVE ID : CVE-2018-5712 It was discovered that PHP5 was vulnerable to a reflected cross-site scripting (XSS) attack on the PHAR 404 error page by manipulating the URI of a request for a

Re: jquery CVEs: no-dsa or unsupported? + snyk.io

2018-01-20 Thread Paul Wise
On Fri, Jan 19, 2018 at 11:52 PM, Antoine Beaupré wrote: > I have found that Snyk had issues in its database that weren't in Mitre: > > https://snyk.io/vuln/npm:jquery I note that nodesecurity also has some CVE-less issues: https://nodesecurity.io/advisories?search=jquery > Finally, I wanted