it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4826-1] nodejs security update
- Date: Wed, 6 Jan 2021 22:02:35 +0000
- List-archive: https://lists.debian.org/msgid-search/20210106220235.GA8316 AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=8V7uK7+2dpp5v93l37lVBkolhEawCFgYm1tc1e340wc=; b=TN XaruGTBfuN/7mrQN8Jq9UGYvbhvboc/ik7OXTDnHigSfbCLlmWqEI9I0DEtXBx56uuaEmesNfr0eF 6XyoeRLbCSNEnRyZO8G/lW22kZ9WDgk/qvyFLIxhKHkv2rCbyJVk85CIYFyPgxyaN8Z95Ipm4yx1X 6sx95FSUya4RNjDitLqnPepAJXiTp8CAS6A4ULBG3xScCr0VLjeJ5PNuVZsGW8C4iobRJSj/QsLgd VyGcL+3Avvsv6ao7bn1thG9lLbXZONFSpoOZe9krzHM0J40v9VosdNO1PXz634dJy/j7pOdLBhEts 8VPSV0R5BQxoK7VWbQgnxwSXMj3eV3SQ==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Wed, 6 Jan 2021 22:02:51 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <IRiv6vQBIo.A.vi.LOj9fB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4826-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
January 06, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : nodejs
CVE ID : CVE-2020-8265 CVE-2020-8287
Two vulnerabilities were discovered in Node.js, which could result in
denial of service and potentially the execution of arbitrary code or
HTTP request smuggling.
For the stable distribution (buster), these problems have been fixed in
version 10.23.1~dfsg-1~deb10u1.
We recommend that you upgrade your nodejs packages.
For the detailed security status of nodejs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nodejs
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl/2MjIACgkQEMKTtsN8
TjZGHg//SC9/yOWGcK+Fxa3+lVx7IwBP9GYfonEJNlODfs7gCHU0+iSk5bkqNixE
5lEpbo4eIeaWCYk06RcxsdSjlX7ha20HDRkfdFc0Yhyz9Q3Nw6Smk8MWIqMxYgDi
hljL4oU1sdtmSGl4WPy5g4qyO1c48GoF2VPaP0qJfT1QGVA1yjOL3jijDluSJ7dI
BVzM6dwYZBM3wZNL8PGAy7jFg7vUgvPvdCTHuFa6WD/zJ8HXQp1+VHs+NjtfvGDr
iLx3S3iYwuELlST9pAVrgUUTIQXf4HSwK4NkjvtBIpapxEO7RSb9XZL4er4HQF78
B4E6P1mlgvn4B71GqdRZBc6AHAguJa6t6BgYSztTI+staOX6djJkLYR+RTA0ttO8
1J63aA3a4viDyvgwi+OmQY24QwbM2pJPhM+c9j8P3ZxqDdJriLKp6UAX2ho0McgA
ev1VZnpYFhT+W3aYRhkdVKhw7lDWIjGfJTj3De6Oy1H2OOd+Z+1IrMmVh1OSKExa
0+Xe4FrKyU8+jL7vR6m5C9NEOEM/OlgJNo0FkNbotAWZ1E7CICUUOPLJsgvK8x3u
WNTmrGkvsOJTUczj80clym34Yq3nqYctvYxPJsX9zIV+9AqO0AAqAXzYbWZytFss
I7zWIEPC5YANxkd9ArX6fAsU7HSS9hBOX5E8zKRDT+AiPjiE2wk=
=v7wl
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4826-1] nodejs security update, Moritz Muehlenhoff, 06.01.2021
Archiv bereitgestellt durch MHonArc 2.6.24.