[Secure-testing-commits] r56219 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Sep 28 11:40:43 UTC 2017


Author: carnil
Date: 2017-09-28 11:40:43 +0000 (Thu, 28 Sep 2017)
New Revision: 56219

Modified:
   data/CVE/list
Log:
Add nodejs issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-28 11:29:50 UTC (rev 56218)
+++ data/CVE/list	2017-09-28 11:40:43 UTC (rev 56219)
@@ -33,7 +33,9 @@
 CVE-2017-14850
 	RESERVED
 CVE-2017-14849 (Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended ...)
-	TODO: check
+	- nodejs <not-affected> (Vulnerable code introduced in 8.5.0)
+	NOTE: https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/
+	NOTE: https://twitter.com/nodejs/status/913131152868876288
 CVE-2017-14848
 	RESERVED
 CVE-2017-14847 (Mojoomla WPAMS Apartment Management System for WordPress allows SQL ...)




More information about the Secure-testing-commits mailing list