Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4863-1] nodejs security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4863-1] nodejs security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4863-1] nodejs security update
  • Date: Wed, 24 Feb 2021 19:25:39 +0000
  • List-archive: https://lists.debian.org/msgid-search/20210224192539.GB13517 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=cWBVwQkV7unKFgUPCRsz5lIZfkqVhu+9M0RZtozUnAA=; b=C8 diubndh6iReFcavZx3360TiOymm7uQ6DiCQXBL34Jmgn6acF6cOxoawxVoPuTQok/agOX0BongNwq JxLGxDZHooTrtU6rgOHsR11mzIthMkBNYVp2Wjd/Gs0s2bQ36dajAzQZ5Motfthudo3gaEEfT4GPp ea9KJIm7pKFcYL2Ileu2hdt61jX5tDEc55SuSZcBf/mcZFtqnkQ5JhAa6h2Z+UTuK1uDZFtfZzAVs p0hQxhzz5ZJ4VrMWaAmq67DhIXpL07ktGoL3xlTtL2qVha5GWwzVdBQpk+Dnlg2PPJeyATRHi/5h3 bvch2Y4NR3DkBhWqiQI+rheyz9bTFQjg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Wed, 24 Feb 2021 19:25:56 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <7BrluLMSHxB.A.cMG.EhqNgB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4863-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
February 24, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nodejs
CVE ID : CVE-2021-22883 CVE-2021-22884

Two vulnerabilities were discovered in Node.js, which could result in
denial of service or DNS rebinding attacks.

For the stable distribution (buster), these problems have been fixed in
version 10.24.0~dfsg-1~deb10u1.

We recommend that you upgrade your nodejs packages.

For the detailed security status of nodejs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nodejs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmA2pXsACgkQEMKTtsN8
TjZPZRAAnKJXhRwilLozjwNQVy0SPwubaHrhdmcnSToVIRwrMwUZUKQSfG2kIE0P
VeS+tRMrng0u7g7OaNiirIpPhmHybKGAvz8TW4pIQG48YFWezKoFG2lVlfvF9J4j
4Rf7SrcXov/XERIE+h/FB3SntGKIz2kTeAlmAgJRAmpojPL0V5KycVrq14Q9/Aor
7sh9Ly5kkZwKjB0+ZBzSIb2jteb5TOvv15lLcK271dEdDLbTxzgRGpHpVXodRaOT
NBm6KREK5tQrIYNw5bVMQCDAJo+wRZ91JLIyRkXXEYprpB+3elBZyai78WOZA3NV
PmiFQnIsu/nH+82ShCx68f7YWvP/0pdS76nMO5d+6bYZ1YXIkJ9Dpw3sbiY5+FmL
DYecZZcnDoPOj3K03l0thdiLaAlNLsolDvDwmfu/w3qInysybPkKxHNTCin1DZ1J
DoX2oLfC7tnAyEwH/t5XOQsPI9DXyQBRn4bDisLYRcnS3TSOFF3eFVCQ8KHU9k+b
oCkOfRhRJ3xJbxQxlXQtR9ZWFX+EVO0GzyFnqjYlLTIDsoQl8i7tcG5ewZ7xOxeL
6oWdwstNltWK4XNFFTW8hkk4TJiVlBojkEbAk/2L0poQPsoU5YiGDxcPtHD+2H57
wQMoL8oFdnPrc8RHGJ2pqwXXHEot+96V+Rb+KOKbtaZejxDuEdA=
=32dq
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4863-1] nodejs security update, Moritz Muehlenhoff, 24.02.2021

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang