[Git][security-tracker-team/security-tracker][master] node-sha.js DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 16 18:39:55 BST 2025
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e95d3855 by Moritz Mühlenhoff at 2025-09-16T19:37:22+02:00
node-sha.js DSA
- - - - -
2 changed files:
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,7 @@
+[16 Sep 2025] DSA-6002-1 node-sha.js - security update
+ {CVE-2025-9288}
+ [bookworm] - node-sha.js 2.4.11+~2.4.0-2+deb12u1
+ [trixie] - node-sha.js 2.4.11+~2.4.0-2+deb13u1
[14 Sep 2025] DSA-6001-1 cjson - security update
{CVE-2025-57052}
[bookworm] - cjson 1.7.15-1+deb12u4
=====================================
data/dsa-needed.txt
=====================================
@@ -50,8 +50,6 @@ mbedtls/oldstable
--
netty
--
-node-sha.js (jmm)
---
opennds/oldstable
pinged maintainer, but no reply yet. should most probably be bumped to 10.x
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e95d38552f753c3c3dbfc3a5d626bec08bb63250
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e95d38552f753c3c3dbfc3a5d626bec08bb63250
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250916/0fd7aaac/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list