[Git][security-tracker-team/security-tracker][master] add nodejs issue (seems missed in the blog post) and commit references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Feb 23 13:52:56 GMT 2024
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0186c260 by Moritz Muehlenhoff at 2024-02-23T14:52:03+01:00
add nodejs issue (seems missed in the blog post) and commit references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,8 @@
+CVE-2024-22025
+ - nodejs 18.19.1+dfsg-1
+ NOTE: https://nodejs.org/en/blog/release/v18.19.1
+ NOTE: https://github.com/nodejs/node/commit/f31d47e135973746c4f490d5eb635eded8bb3dda (v18.x)
+ NOTE: https://github.com/nodejs/node/commit/9052ef43dc2d1b0db340591a9bc9e45a25c01d90 (main)
CVE-2024-26593 [i2c: i801: Fix block process call transactions]
- linux <unfixed>
NOTE: https://git.kernel.org/linus/c1c9d0f6f7f1dbf29db996bd8e166242843a5f21 (6.8-rc5)
@@ -1571,6 +1576,8 @@ CVE-2024-21896 (The permission model protects itself against path traversal atta
CVE-2024-22019 (A vulnerability in Node.js HTTP servers allows an attacker to send a s ...)
- nodejs 18.19.1+dfsg-1 (bug #1064055)
NOTE: https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-cve-2024-22019---high
+ NOTE: https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 (v18.x)
+ NOTE: https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 (main)
CVE-2024-21892 (On Linux, Node.js ignores certain environment variables if those may h ...)
- nodejs 18.19.1+dfsg-1 (bug #1064055)
[bullseye] - nodejs <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240223/bf8513d9/attachment.htm>
More information about the debian-security-tracker-commits
mailing list