Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5170-1] nodejs security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5170-1] nodejs security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5170-1] nodejs security update
  • Date: Mon, 27 Jun 2022 18:43:09 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/20220627184309.GA5489 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=Bnvwr+3VL7lr7eR5/MuHyQhZtKT3tj7H/1IVsxSPcBo=; b=vZ y7Arf1TpEX09uus38l4vb//CjWSCNSwR20x71nYN+BaDiQiKyu4AuKm3gbxFGIRO4JpC8sipklGX6 ru7q18xsH9L7VPsv7W5oBuNUvrUtrrCUMWxsCQRxA+K8v0FoMXgnn0pSruDQjykUU6wOJH4TacY/V ytkJbFDvukOFNZZKQlT92nJ0gdJesQ8f+kkQj8yD33aNj5ZDA05WKqjcLXe9TJa8C/URAnwIeCzOE wTdbEeYmnw1revUIbyoDgXBg8ZjZcbrEHSGEP5jDZyFaWhpo+ZamzMjSdzrO+ylWkMGq+MOYG2wDB GWBbI00s1a7Bh97Eav43Xlbb4P6hkWmw==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Mon, 27 Jun 2022 18:43:26 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <zRvCGG18mcJ.A.IsG.NpfuiB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5170-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
June 27, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nodejs
CVE ID : CVE-2021-22959 CVE-2021-22960 CVE-2021-44532 CVE-2021-44533
CVE-2022-21824 CVE-2021-44531

Multiple vulnerabilities were discovered in Node.js, which could result in
HTTP request smuggling, a bypass of certificate verification or prototype
pollution.

For the stable distribution (bullseye), these problems have been fixed in
version 12.22.12~dfsg-1~deb11u1.

We recommend that you upgrade your nodejs packages.

For the detailed security status of nodejs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nodejs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmK5+foACgkQEMKTtsN8
TjbGrg/+PU+oRJ5ARjKwXR1aCdxMvhdzanyaAP7nVeo+iHQwl+13U958e9TpadqX
5gBmmlkWM7vcHHr5Anw6gGptF5L2NTj/Hid4SDFswNLCzqbIm9eIl0FFg2n7ilGD
ISZtXEV089UUzCSat1Nk3A7eq3ShESWciFhHkwhejZKzcTJgbzAPFbZSazOfYaXP
JREl8OnFg9WWO27gj/zkjHhsG/ZPgJjoGagSfpIuEx3KL/KOiG3eJmJtjS68RVTF
D6Zg6P8iFmQLy/PKZycPXEm5Jp5Zrtan4N6yJl3EHFdjcJTJSmCZy0HlLL97eRle
kVQI5/KgH9Ev1VYPycOg+cPPaBDLpoFO7OtzhZLmq4/IUsEKHOMeNTKZQWYXjDzl
nLANjnHGt7pfw2poXRgblzSikJHiAurJRGarP4k0ebGyy8B6nKrQUlgDI0u4y48z
JiqsP95mwCvwFlrjxSTjG5R7AsEuszytqejyxeg5qqkkQKSONsLj02Eav+QqInUS
D9dHEl4eoBx529Fu3ZWBfTxe4avxFm/HDw2FJDxz0ciP7S/H0+5TyFwym3tmQpY8
pXD49bVCoE5my4JeDEhpZp1YrsQFTv3RUqqLp3T1uUlsdON4Jz3RP4WX4dzIRte+
fJO6fg+26+h7VykuyWSKYYEyFy1dDmGypc93KfNMrU75BztQpsI=
=ELbx
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5170-1] nodejs security update, Moritz Muehlenhoff, 27.06.2022

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang