Debian 9897 Published by

Updated jquery packages has been released for Debian GNU/Linux 8 LTS



Package : jquery
Version : 1.7.2+dfsg-3.2+deb8u6
CVE ID : CVE-2019-11358

jQuery mishandles jQuery.extend(true, {}, ...) because of Object.prototype
pollution. If an unsanitized source object contained an enumerable __proto__
property, it could extend the native Object.prototype. For additional
information, please refer to the upstream advisory at
https://www.drupal.org/sa-core-2019-006 .

For Debian 8 "Jessie", this problem has been fixed in version
1.7.2+dfsg-3.2+deb8u6.

We recommend that you upgrade your jquery packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
  jQuery Security Update for Debian 8 LTS