Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5991-1] nodejs security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5991-1] nodejs security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5991-1] nodejs security update
  • Date: Fri, 29 Aug 2025 18:10:59 +0000
  • Authentication-results: lists.piratenpartei.de; dkim=none; dmarc=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/aLHtMy65rhE1X1tU AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=l4YH+8uAQxzNAiY47nXKYKP2T85ZFxjy5facWF/ySDk=; b=cF uFSJ5x6SRr62rEx+Ukar8PHFjrWDmq9vy30sdYDGrqvNBToY3SqOve1Xnj1qJdyPky87B21/2D0hE Wcm4Oa5jrgp5U7fjBId2IJ9x/COvD8ET3TMi/uHJYa8OWcLbjiQwJ2zu5MGWdg9yYPQe+H4gRSVbm qo2CrpHtqk+V4vqOpQhssXNFhY/OXQ7e+1OyELtiibQi4Gnfm2Q1IMUQJmrI0CBNNz7JmIu6uojd1 V+KT3gYB+DO5xS9xxAdlTaXFdYYmVk71iwUapgsY5LpPjRR9EiDD0eyggszlzGYMN9wGQ/KKuXRoL 8EpSOXYIpqo1aCNsulqdcRckf1j/EflA==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Fri, 29 Aug 2025 18:11:25 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <5dn229HyBiN.A.m4tP.N1esoB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5991-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 29, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nodejs
CVE ID : CVE-2023-46809 CVE-2024-21892 CVE-2024-22019
CVE-2024-22020 CVE-2024-22025 CVE-2024-27982
CVE-2024-27983 CVE-2025-47153

Multiple vulnerabilities were discovered in Node.js, which could result
in denial of service, HTTP request smuggling, privilege escalation, a
side channel attack against PKCS#1 1.5 or a bypass of network import
restrictions.

For the oldstable distribution (bookworm), these problems have been fixed
in version 18.20.4+dfsg-1~deb12u1.

We recommend that you upgrade your nodejs packages.

For the detailed security status of nodejs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nodejs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmix6wEACgkQEMKTtsN8
TjbvSg//dk+LUYWD/3ztcNzZnP+/2lNclPO+iMZdPtOWAGIGMlWUciVJuWkC6AO6
jPdLAFqQLtWAnEJALn4wt4SZifCBrgU/QKOEoddwokVANn0aMM9lR4vmBa527f2F
Q4DMDa+pyEDlKAhbc3w3aJobRDmdO7WncPP7TK7A2WXJJ0aron9aQCRNXqtMOK5m
GnY1awu6gvCAiJWwsf1N+/gVM11KBiGlL/12FWxK7FiXdlHbNvvx/OO/d4INNuxw
y2Xn/faELbEU9ecMWxUh+kmHd+mqX2tNhAbOH85qrkUU1wfUMrO07sCEAnAaApuj
9+jtZzBdeDOi1xR4MIrH4JxliD656zJHX9wKSIOb+p4vZ86o2/L7EaWtmmDWdCdA
xsxhGNxtq6DCip5GxO5pLO0ftGToXar6zZbrou+kE5oXp2xLAtO/jgiPPAOl7HBg
k78tbCZdxiFy0F+HzDQZFAct5xYKU9eaNHYVAXZF48BW4u38XsievMmSg1aVGpZs
XzSwy2BKYkhC1bD/2ISApvZrcBcgxXbXOQXXEsxiFK7IUPtHcR3Mc9uRgP/KRNQ/
x/WYShdmhSQTlvORv5UeAmEjZqYcRS7qYQQ3tk09coY22NAUl+CfzrIuPCvkY/Gc
DaIbudBi4HcPnmYJAe7GpR6Jw+rSnDdfJXVN6D3SRy2IfVLMVPU=
=mHjX
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5991-1] nodejs security update, Moritz Muehlenhoff, 29.08.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang