[Git][security-tracker-team/security-tracker][master] 2 commits: angular.js triagge for bullseye
Bastien Roucariès (@rouca)
rouca at debian.org
Wed Feb 18 20:09:20 GMT 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
69f40fb8 by Bastien Roucariès at 2026-02-18T21:08:27+01:00
angular.js triagge for bullseye
- - - - -
8f6f7659 by Bastien Roucariès at 2026-02-18T21:08:58+01:00
Remove angular.js from dla-needed.txt
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -69185,6 +69185,7 @@ CVE-2025-4690 (A regular expression used by AngularJS' linky https://docs.angula
- angular.js <unfixed> (bug #1126778)
[trixie] - angular.js <no-dsa> (Minor issue)
[bookworm] - angular.js <no-dsa> (Minor issue)
+ [bullseye] - angular.js <postponed> (Minor issue; whole API is unsafe)
NOTE: https://www.herodevs.com/vulnerability-directory/cve-2025-4690
NOTE: https://codepen.io/herodevs/pen/RNNEPzP/751b91eab7730dff277523f3d50e4b77
NOTE: vulnerable REDOS: https://salsa.debian.org/js-team/angular.js/-/blob/4ff98f444e79456ecc442efd4369db6c423e88e1/src/ngSanitize/filter/linky.js#L131
=====================================
data/dla-needed.txt
=====================================
@@ -39,9 +39,6 @@ amd64-microcode
NOTE: 20251224: See also 1109035#52 for updates from maintainer,
NOTE: 20251224: I think the required kernel microcode driver patch are: https://lists.openwall.net/linux-kernel/2025/10/27/1012
--
-angular.js
- NOTE: 20260216: Added by Front-Desk (rouca)
---
ansible (lee)
NOTE: 20240915: Added by Front-Desk (ta)
NOTE: 20241103: Fixed sid, bookworm, and bullseye (rouca)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/36f86caadab82b6c8701cec6c03a26960b881d1c...8f6f7659a6a5448066a3fa6a93804a8480ecd473
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/36f86caadab82b6c8701cec6c03a26960b881d1c...8f6f7659a6a5448066a3fa6a93804a8480ecd473
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260218/82bf8ef6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list