• [SECURITY] [DSA 4826-1] nodejs security update

    From Moritz Muehlenhoff@21:1/5 to All on Wed Jan 6 23:10:02 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4826-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 06, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : nodejs
    CVE ID : CVE-2020-8265 CVE-2020-8287

    Two vulnerabilities were discovered in Node.js, which could result in
    denial of service and potentially the execution of arbitrary code or
    HTTP request smuggling.

    For the stable distribution (buster), these problems have been fixed in
    version 10.23.1~dfsg-1~deb10u1.

    We recommend that you upgrade your nodejs packages.

    For the detailed security status of nodejs please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/nodejs

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl/2MjIACgkQEMKTtsN8 TjZGHg//SC9/yOWGcK+Fxa3+lVx7IwBP9GYfonEJNlODfs7gCHU0+iSk5bkqNixE 5lEpbo4eIeaWCYk06RcxsdSjlX7ha20HDRkfdFc0Yhyz9Q3Nw6Smk8MWIqMxYgDi hljL4oU1sdtmSGl4WPy5g4qyO1c48GoF2VPaP0qJfT1QGVA1yjOL3jijDluSJ7dI BVzM6dwYZBM3wZNL8PGAy7jFg7vUgvPvdCTHuFa6WD/zJ8HXQp1+VHs+NjtfvGDr iLx3S3iYwuELlST9pAVrgUUTIQXf4HSwK4NkjvtBIpapxEO7RSb9XZL4er4HQF78 B4E6P1mlgvn4B71GqdRZBc6AHAguJa6t6BgYSztTI+staOX6djJkLYR+RTA0ttO8 1J63aA3a4viDyvgwi+OmQY24QwbM2pJPhM+c9j8P3ZxqDdJriLKp6UAX2ho0McgA ev1VZnpYFhT+W3aYRhkdVKhw7lDWIjGfJTj3De6Oy1H2OOd+Z+1IrMmVh1OSKExa 0+Xe4FrKyU8+jL7vR6m5C9NEOEM/OlgJNo0FkNbotAWZ1E7CICUUOPLJsgvK8x3u WNTmrGkvsOJTUczj80clym34Yq3nqYctvYxPJsX9zIV+9AqO0AAqAXzYbWZytFss I7zWIEPC5YANxkd9ArX6fAsU7HSS9hBOX5E8zKRDT+AiPjiE2wk=
    =v7wl
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)