Skip to content
Commit da2c227c authored by Salvatore Bonaccorso's avatar Salvatore Bonaccorso
Browse files

Mark CVE-2019-10086 as no-dsa for stretch and buster

When applying the patch for CVE-2019-10086 the library switches the
default to be secured, and instead one needs to opt-out vs. opt-in and
allow access to the 'class' property.

Might need investigation of affected reverse dependencies for functional
regressions if this is applied for stable releases. This might be safe,
as at least Red Hat and SUSE seem to have done the switch in some of
their products.
parent 355ba237
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment