[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for nodejs issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Oct 28 08:49:03 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
64b780a6 by Salvatore Bonaccorso at 2023-10-28T09:48:30+02:00
Add Debian bug reference for nodejs issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1132,7 +1132,7 @@ CVE-2023-5625
 	- python-eventlet <not-affected> (Red Hat-specific regression)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2244717
 CVE-2023-39333
-	- nodejs <unfixed>
+	- nodejs <unfixed> (bug #1054892)
 	[bullseye] - nodejs <not-affected> (Only affects 18.x and later)
 	[buster] - nodejs <not-affected> (Only affects 18.x and later)
 	NOTE: https://nodejs.org/en/blog/vulnerability/october-2023-security-releases#code-injection-via-webassembly-export-names-low---cve-2023-39333
@@ -1925,7 +1925,7 @@ CVE-2023-39277 (SonicOS post-authentication stack-based buffer overflow vulnerab
 CVE-2023-39276 (SonicOS post-authentication stack-based buffer overflow vulnerability  ...)
 	NOT-FOR-US: SonicOS
 CVE-2023-38552 (When the Node.js policy feature checks the integrity of a resource aga ...)
-	- nodejs <unfixed>
+	- nodejs <unfixed> (bug #1054892)
 	[bullseye] - nodejs <not-affected> (Only affects 18.x and later)
 	[buster] - nodejs <not-affected> (Only affects 18.x and later)
 	NOTE: https://nodejs.org/en/blog/vulnerability/october-2023-security-releases#integrity-checks-according-to-policies-can-be-circumvented-medium---cve-2023-38552



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/64b780a63ea6933076b95cfe2065e74809e45eee

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/64b780a63ea6933076b95cfe2065e74809e45eee
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231028/08921905/attachment.htm>


More information about the debian-security-tracker-commits mailing list