Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 81782594 by Salvatore Bonaccorso at 2018-12-26T16:19:15Z Add fixed version for CVE-2018-3740/ruby-sanitize in unstable - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -51885,7 +51885,7 @@ CVE-2018-3741 (There is a possible XSS vulnerability in all rails-html-sanitizer NOTE: https://github.com/rails/rails-html-sanitizer/commit/f3ba1a839a35f2ba7f941c15e239a1cb379d56ae CVE-2018-3740 (A specially crafted HTML fragment can cause Sanitize gem for Ruby to ...) [experimental] - ruby-sanitize 4.6.5-1 - - ruby-sanitize <unfixed> (bug #893610) + - ruby-sanitize 4.6.6-1 (bug #893610) [jessie] - ruby-sanitize <ignored> (Only occurs with libxml2 >= 2.9.2, jessie has 2.9.1) NOTE: https://github.com/rgrove/sanitize/issues/176 NOTE: https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8178259445cd3a9bd74fb3930987a0385bc432d0 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8178259445cd3a9bd74fb3930987a0385bc432d0 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits