-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-4826-1
security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 06, 2021
https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : nodejs
CVE ID : CVE-2020-8265 CVE-2020-8287
Two vulnerabilities were discovered in Node.js, which could result in
denial of service and potentially the execution of arbitrary code or
HTTP request smuggling.
For the stable distribution (buster), these problems have been fixed in
version 10.23.1~dfsg-1~deb10u1.
We recommend that you upgrade your nodejs packages.
For the detailed security status of nodejs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nodejs
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:
https://www.debian.org/security/
Mailing list:
debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl/2MjIACgkQEMKTtsN8 TjZGHg//SC9/yOWGcK+Fxa3+lVx7IwBP9GYfonEJNlODfs7gCHU0+iSk5bkqNixE 5lEpbo4eIeaWCYk06RcxsdSjlX7ha20HDRkfdFc0Yhyz9Q3Nw6Smk8MWIqMxYgDi hljL4oU1sdtmSGl4WPy5g4qyO1c48GoF2VPaP0qJfT1QGVA1yjOL3jijDluSJ7dI BVzM6dwYZBM3wZNL8PGAy7jFg7vUgvPvdCTHuFa6WD/zJ8HXQp1+VHs+NjtfvGDr iLx3S3iYwuELlST9pAVrgUUTIQXf4HSwK4NkjvtBIpapxEO7RSb9XZL4er4HQF78 B4E6P1mlgvn4B71GqdRZBc6AHAguJa6t6BgYSztTI+staOX6djJkLYR+RTA0ttO8 1J63aA3a4viDyvgwi+OmQY24QwbM2pJPhM+c9j8P3ZxqDdJriLKp6UAX2ho0McgA ev1VZnpYFhT+W3aYRhkdVKhw7lDWIjGfJTj3De6Oy1H2OOd+Z+1IrMmVh1OSKExa 0+Xe4FrKyU8+jL7vR6m5C9NEOEM/OlgJNo0FkNbotAWZ1E7CICUUOPLJsgvK8x3u WNTmrGkvsOJTUczj80clym34Yq3nqYctvYxPJsX9zIV+9AqO0AAqAXzYbWZytFss I7zWIEPC5YANxkd9ArX6fAsU7HSS9hBOX5E8zKRDT+AiPjiE2wk=
=v7wl
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)