Your message dated Mon, 24 May 2021 17:30:36 +0200
with message-id <[email protected]>
and subject line Re: [Pkg-javascript-devel] Bug#988726: CVE-2020-28496
has caused the Debian Bug report #988726,
regarding CVE-2020-28496
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
988726: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988726
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: three.js
Severity: important
Tags: security
X-Debbugs-Cc: Debian Security Team <[email protected]>

This was assigned CVE-2020-28496:
https://github.com/mrdoob/three.js/issues/21132
https://github.com/mrdoob/three.js/pull/21143/commits/4a582355216b620176a291ff319d740e619d583e

Cheers,
        Moritz  

--- End Message ---
--- Begin Message ---
Am Tue, May 18, 2021 at 09:04:09PM +0200 schrieb Yadd:
> Le 18/05/2021 à 20:28, Moritz Muehlenhoff a écrit :
> > Source: three.js
> > Severity: important
> > Tags: security
> > X-Debbugs-Cc: Debian Security Team <[email protected]>
> > 
> > This was assigned CVE-2020-28496:
> > https://github.com/mrdoob/three.js/issues/21132
> > https://github.com/mrdoob/three.js/pull/21143/commits/4a582355216b620176a291ff319d740e619d583e
> > 
> > Cheers,
> >         Moritz      
> 
> Hi,
> 
> vulnerable code seems not present in version 111.

Confirmed, 111 seems in fact not affected. I'm updating the security tracker 
and closing
this bug.

Cheers,
        Moritz

--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to