Bug#1032977: Bug#1032976: unblock: node-sqlite3/5.1.5+ds1-1

2023-03-15 Thread Yadd
On 3/15/23 11:40, Jonathan Wiltshire wrote: It's a bit noisy with the other stuff from the upstream release, but I can see the argument for sticking with it rather than cherry-picking. Unblocked. Thanks Jonathan! I pushed also an unblock request for Apache 2.4.56. Since we decide to follow up

Bug#1032976: unblock: node-sqlite3/5.1.5+ds1-1

2023-03-15 Thread Jonathan Wiltshire
Hi, On Wed, Mar 15, 2023 at 06:33:08AM +0400, Yadd wrote: > Please unblock package node-sqlite3 > > [ Reason ] > A code execution vulnerability was discover in node-sqlite3 due to the > underlying implementation of .toString(). It is then possible to execute > arbitrary JavaScript or to achieve a

Bug#1032976: unblock: node-sqlite3/5.1.5+ds1-1

2023-03-14 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: node-sqli...@packages.debian.org Control: affects -1 + src:node-sqlite3 Please unblock package node-sqlite3 [ Reason ] A code execution vulnerability was discover in node-sqli