it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5539-1] node-browserify-sign security update
- Date: Mon, 30 Oct 2023 16:25:31 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1qxV51-00Ddrq-JJ AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=HpRZlqy2WE4OYQ9aa352tUHQ82zceuDrWYgcNvdWlUo=; b=bG Y06eD1D3qYVF3CB79cq9L1TwF7IyuJeoxXcmz+4kcU7adP60tjw5GC/uufhpct2vLeYbb3HYlODcJ N0xMF5FlArER+3tClmm4c5lLQ1v099ar1rbr3HGZ7qMlv3gOnA/RMUQCpe2ufjYwik4nLmePoC+XL JqRsCAes3isi+yVK8ah23Ctdyv7MNVYJ/pbGuQrSMQlnT43mJRXToqBRbmY0Kqd/rbjoOd4QKYQb2 EgOh5AmtB6PjIPKK5eGeinlPmU4rOUxz0NUP5FbyZl3pcnum7x7GHnLg5NUZi6tEAyuDepErNWOwG 9hnbfaXA7LTsI/arUUX0kRN543zhwBcA==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Mon, 30 Oct 2023 16:25:53 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <R9VeJe7HSbH.A.KUD.Rk9PlB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5539-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
October 30, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : node-browserify-sign
CVE ID : CVE-2023-46234
Debian Bug : 1054667
It was reported that incorrect bound checks in the dsaVerify function
in node-browserify-sign, a Node.js library which adds crypto signing
for browsers, allows an attacker to perform signature forgery attacks
by constructing signatures that can be successfully verified by any
public key.
For the oldstable distribution (bullseye), this problem has been fixed
in version 4.2.1-1+deb11u1.
For the stable distribution (bookworm), this problem has been fixed in
version 4.2.1-3+deb12u1.
We recommend that you upgrade your node-browserify-sign packages.
For the detailed security status of node-browserify-sign please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/node-browserify-sign
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmU/2K5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SYeRAAmffcSYdBfiH/6U30rpfiLylS8zL/ca2sILLKmfYuwG/DH6n5BJ5n+oos
RrXpXhOXjhLmTe1f9Sst3hXCv0IIsJoITnrlmfSjp0CmTk3jx/VhQljSeFUCAFUk
pyAL27QB76SSwqiJNNqvbKEwwatdtNyNFs/zE7Ir7lFT7hKLwryv70Mwf1xWdh59
ZFMaCGPntGWpgwSHy88kD/z6Oo3SV/Q+U73Y53Rv62ZZMNrX1ploVsI1zPLFrOQS
NkUwT+nGCfe13S5GUZ/w5U/joEjXWlDbPH8VSnL7pFBudVP6h6NcgyHds7jYsHbZ
AuViuE0ctEu2li/j51fD6MOZu2HRtaxi6EuZpaOTUDbq1qC5GvGa0+4FuNBVO3k3
3N+4fVARStFoWFnoqX8+0kWJvkhvO8O8AVoIMRzWEbLjeBv5nMHxggRfw2cisJeN
TGIDvJfDiC7w18TDEIwDwEo1nScCWndPK5LPkI6+j9VQIVKdf9UGJS+pnWgywT9G
6EiSKS+pOQSujNV5XuWDeicV2e3CvgrVQ+kaOKvFBgpGfZwOFV2+324kCnAk1hMu
pAnn7/7e/NYdDhpzmAv6fD5GfiW8WhLgRkNpKAQwoPV1Ywwr9S9KBxsWK2Lf1W4t
6RyyKKX8M+gz7rLmeGfjJ4fbGdn/xSH7IWXjBCOiN1W+gwNmsCg=
=htaY
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5539-1] node-browserify-sign security update, Salvatore Bonaccorso, 30.10.2023
Archiv bereitgestellt durch MHonArc 2.6.24.