[Pkg-javascript-devel] Bug#692434: yui: CVE-2012-5475 - YUI 2.x security issue regarding embedded SWF files

Moritz Muehlenhoff jmm at inutil.org
Wed Nov 7 17:36:08 UTC 2012


On Tue, Nov 06, 2012 at 10:15:51AM +0100, Luciano Bello wrote:
> Package: yui
> Severity: grave
> Tags: security
> Justification: user security hole
> 
> Hi,
> please see :
> http://www.yuiblog.com/blog/2012/10/30/security-announcement-swf-vulnerability-
> in-yui-2/
> 
> Are vulnerable versions in Debian?

More details are now available:
http://yuilibrary.com/support/20121030-vulnerability/

Cheers,
        Moritz



More information about the Pkg-javascript-devel mailing list