Your message dated Sat, 20 Mar 2021 08:21:26 +0000
with message-id <e1lnwro-000dwz...@fasolo.debian.org>
and subject line Bug#985568: fixed in node-ua-parser-js 0.7.24+ds-1
has caused the Debian Bug report #985568,
regarding node-ua-parser-js: CVE-2021-27292
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
985568: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=985568
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: node-ua-parser-js
Version: 0.7.23+ds-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Control: found -1 0.7.14-1 

Hi,

The following vulnerability was published for node-ua-parser-js.

CVE-2021-27292[0]:
| ua-parser-js &gt;= 0.7.14, fixed in 0.7.24, uses a regular expression
| which is vulnerable to denial of service. If an attacker sends a
| malicious User-Agent header, ua-parser-js will get stuck processing it
| for an extended period of time.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-27292
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27292
[1] 
https://github.com/faisalman/ua-parser-js/commit/809439e20e273ce0d25c1d04e111dcf6011eb566
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1940613

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-ua-parser-js
Source-Version: 0.7.24+ds-1
Done: Yadd <y...@debian.org>

We believe that the bug you reported is fixed in the latest version of
node-ua-parser-js, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 985...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Yadd <y...@debian.org> (supplier of updated node-ua-parser-js package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 20 Mar 2021 08:56:15 +0100
Source: node-ua-parser-js
Architecture: source
Version: 0.7.24+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<pkg-javascript-de...@lists.alioth.debian.org>
Changed-By: Yadd <y...@debian.org>
Closes: 985568
Changes:
 node-ua-parser-js (0.7.24+ds-1) unstable; urgency=medium
 .
   * Team upload
   * Fix debian/watch
   * New upstream version 0.7.24+ds (Closes: #985568, CVE-2021-27292)
Checksums-Sha1: 
 ec37b6996e0256ce2bec5833a66b98c0c252a51d 2166 node-ua-parser-js_0.7.24+ds-1.dsc
 d525ebf337494116c2855915205c46b07a29460a 30864 
node-ua-parser-js_0.7.24+ds.orig.tar.xz
 1d05a8d687664da60df222eb2888d85560f1d801 3052 
node-ua-parser-js_0.7.24+ds-1.debian.tar.xz
Checksums-Sha256: 
 361f6681b64109e93574dd8495ccacba5b0b9faa3e2c77bcce07250c7eab6b1b 2166 
node-ua-parser-js_0.7.24+ds-1.dsc
 936d8d78af0b4f45288566d4477ca2984889c38ed0bcff8a2e60f2ea2a8e1343 30864 
node-ua-parser-js_0.7.24+ds.orig.tar.xz
 6241ec1364f1f7c92a6961242aaada34bba62522ced5a329200e8f5701658885 3052 
node-ua-parser-js_0.7.24+ds-1.debian.tar.xz
Files: 
 bcddd1e0970cf532981f937269391e09 2166 javascript optional 
node-ua-parser-js_0.7.24+ds-1.dsc
 da72edc656819064bd49e2a995a22b19 30864 javascript optional 
node-ua-parser-js_0.7.24+ds.orig.tar.xz
 c81e074033b5b12e3d962b6056bdbe76 3052 javascript optional 
node-ua-parser-js_0.7.24+ds-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmBVqw4ACgkQ9tdMp8mZ
7un6IxAAnN+YzLoyHtYgJYojRFj8bjQN1LY3PXIq+c4aipVafNjOo2QY9FRWLnjw
q6212H22x7DN/VRfs0Kub4fFl9v83yjU+hOJUQgGTQk0IubN/23XuaGM9cZnKyPe
TQQOWkHfKv8uNzMc88c/0EpAcnAhP40pVgiM8YrLIfQg1fylGOA8cC2t1THzkhww
EWrS0oFOuDrBURqfUyIzG/5m6QWQbK2iosXteuQJf4ISckDOMyG1CvyCHKRMpt89
IpgrkWBxgQ/EFkZlS8A0n9ZqI3vHGVU6NRTxmcI0qI7hU8C2wqRAtAdE0N7RoIpT
xclkIT7TP31CLuGULCpyXj3/2IMnfZh75HRdL1YlntE55Qheqsr+PsMr7mbs/bSK
21chuEdZ7V9KJoMdE9jbTHzqpbLGl4q0bKVxr7BKGyfFu13LDKd8ftX6r1wIOyOK
EyGZhsGPrKXximSsAFp9DXwFxG/Qg01loRuU2t0ZUbtQWb6rnahBUbxXWMVV21Oo
i6idWRdBcQcvn3Jrf8RxDyEOJJZr0NODubICfhxD11aBL1NlP1+14dNYXlF9dU//
jo0MQBo/twQfRMAek1iSzRvQ12jwAD2H4MFF2bpQF18rQOea+R5D3jQSsXAiy+6h
U34ZS6jYV3p3G63z35V0PkBhd3kTqi//Q2O+1CWeYWgThP4Vc5Y=
=2iv8
-----END PGP SIGNATURE-----

--- End Message ---
-- 
Pkg-javascript-devel mailing list
Pkg-javascript-devel@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to