Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0186c260 by Moritz Muehlenhoff at 2024-02-23T14:52:03+01:00
add nodejs issue (seems missed in the blog post) and commit references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,8 @@
+CVE-2024-22025
+       - nodejs 18.19.1+dfsg-1
+       NOTE: https://nodejs.org/en/blog/release/v18.19.1
+       NOTE: 
https://github.com/nodejs/node/commit/f31d47e135973746c4f490d5eb635eded8bb3dda 
(v18.x)
+       NOTE: 
https://github.com/nodejs/node/commit/9052ef43dc2d1b0db340591a9bc9e45a25c01d90 
(main)
 CVE-2024-26593 [i2c: i801: Fix block process call transactions]
        - linux <unfixed>
        NOTE: 
https://git.kernel.org/linus/c1c9d0f6f7f1dbf29db996bd8e166242843a5f21 (6.8-rc5)
@@ -1571,6 +1576,8 @@ CVE-2024-21896 (The permission model protects itself 
against path traversal atta
 CVE-2024-22019 (A vulnerability in Node.js HTTP servers allows an attacker to 
send a s ...)
        - nodejs 18.19.1+dfsg-1 (bug #1064055)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-cve-2024-22019---high
+       NOTE: 
https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 
(v18.x)
+       NOTE: 
https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 
(main)
 CVE-2024-21892 (On Linux, Node.js ignores certain environment variables if 
those may h ...)
        - nodejs 18.19.1+dfsg-1 (bug #1064055)
        [bullseye] - nodejs <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to