control: tag -1 + pending control: tag -1 + fixed-upstream. BTW wheezie is affected too (not squeeze), code is identical than in 4.4. Could you update the security tracker.
Upstream fixed 3.6 here http://dev.ckeditor.com/browser/CKEditor/trunk/_source/plugins/preview/preview.html?rev=7706 On Wed, Sep 10, 2014 at 6:18 PM, Bastien ROUCARIES <roucaries.bast...@gmail.com> wrote: > A new version is under mentors at: > http://mentors.debian.net/debian/pool/main/c/ckeditor/ckeditor_4.4.4+dfsg1-1.dsc > > Stable is problematic. I could not made a patch: > - ckeditor under stable is only min.js (not sourced: S) > - I may with a lot of work create a sourcefull version from svn but it > will be massive surgery. > - I may delete the problematic plugin but package will be still > sourceless and it will loose some functionnality. > > Bastien -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org