Bug#970307: buster-pu: package node-mysql/2.16.0-1+deb10u1

2020-09-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2020-09-14 at 16:04 +0200, Xavier Guimard wrote: > [ Reason ] > node-mysql is vulnerable to CVE-2019-14939 (#934712) > > [ Impact ] > Default "LOAD DATA LOCAL INFILE" is too permissive > > [ Tests ] > Sadly tests were not enabled in buster > I think the int

Processed: Re: Bug#970307: buster-pu: package node-mysql/2.16.0-1+deb10u1

2020-09-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #970307 [release.debian.org] buster-pu: package node-mysql/2.16.0-1+deb10u1 Added tag(s) confirmed. -- 970307: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=970307 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#970307: buster-pu: package node-mysql/2.16.0-1+deb10u1

2020-09-14 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-mysql is vulnerable to CVE-2019-14939 (#934712) [ Impact ] Default "LOAD DATA LOCAL INFILE" is too permissive [ Tests ] Sadly tests were not enabled in buster [ Ri