#1008153 bullseye-pu: package node-node-forge/0.10.0~dfsg-3+deb11u1

#1008153#5
Date:
2022-03-23 10:14:39 UTC
From:
To:
[ Reason ]
node-node-forge signature verification code is lenient in checking the digest
algorithm structure. This can allow a crafted structure that steals padding
bytes and uses unchecked portion of the PKCS#1 encoded message to forge a
signature when a low public exponent is being used. The issue has been
addressed in `node-forge` version 1.3.0.

[ Impact ]
medium vulnerability

[ Tests ]
New test added

[ Risks ]
Low risk, test passed

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Better checks

[ Other info ]
Upstream patch applied without any change

Cheers,
Yadd

#1008153#10
Date:
2022-05-28 20:18:44 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1008153#17
Date:
2022-05-29 18:02:09 UTC
From:
To:
package release.debian.org
tags 1008153 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-node-forge
Version: 0.10.0~dfsg-3+deb11u1

Explanation: fix signature verification issues [CVE-2022-24771 CVE-2022-24772 CVE-2022-24773]

#1008153#22
Date:
2022-05-29 18:02:09 UTC
From:
To:
package release.debian.org
tags 1008153 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-node-forge
Version: 0.10.0~dfsg-3+deb11u1

Explanation: fix signature verification issues [CVE-2022-24771 CVE-2022-24772 CVE-2022-24773]

#1008153#27
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam