#1009345 bullseye-pu: package node-moment/2.29.1+ds-2+deb11u1

#1009345#5
Date:
2022-04-12 04:39:35 UTC
From:
To:
[ Reason ]
node-moment is vulnerable to path traversal (#1009327, CVE-2022-24785)

[ Impact ]
Medium vulnerability

[ Tests ]
No changes in test

[ Risks ]
Low risk, patch is trivial

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Just a new check to prevent names that look like filesystem paths

Cheers,
Yadd

#1009345#10
Date:
2022-04-12 05:43:20 UTC
From:
To:
Sorry, here it is.

Cheers,
Yadd

#1009345#15
Date:
2022-05-28 20:00:55 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1009345#22
Date:
2022-05-29 18:02:17 UTC
From:
To:
package release.debian.org
tags 1009345 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-moment
Version: 2.29.1+ds-2+deb11u1

Explanation: fix path traversal issue [CVE-2022-24785]

#1009345#27
Date:
2022-05-29 18:02:17 UTC
From:
To:
package release.debian.org
tags 1009345 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-moment
Version: 2.29.1+ds-2+deb11u1

Explanation: fix path traversal issue [CVE-2022-24785]

#1009345#32
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam