#1011331 bullseye-pu: package node-raw-body/2.4.1-2+deb11u1

#1011331#5
Date:
2022-05-20 07:47:15 UTC
From:
To:
[ Reason ]
node-raw-body embeds a patch that creates a Denial-of-Service
vulnerability into node-express.

[ Impact ]
Security issue, a simple request can crash any express application

[ Tests ]
I added a test that proves that bug is fixed: it fails with
node-raw-body 2.4.1-2 and succeeds with 2.4.1-2+deb11u1

[ Risks ]
No risk, Debian package is now exactly what upstream wrote.

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Drop patch which replaced node-iconv-lite by node-iconv.

[ Other info ]
Thanks to Michael Lescisin for the report and the fix.

#1011331#10
Date:
2022-05-28 18:53:33 UTC
From:
To:
Control: tags -1 + moreinfo

Why was that change made in the first place? The changelog entry from
2014 isn't particularly helpful.

Regards,

Adam

#1011331#17
Date:
2022-05-28 20:36:52 UTC
From:
To:
Control: tags -1 - moreinfo

Hi Adam,

node-iconv-lite entered in Debian only in 2016. That's why this patch
existed.

Cheers,
Yadd

#1011331#24
Date:
2022-05-28 21:18:14 UTC
From:
To:
Control: tags -1 + confirmed
[...]

Thanks for the explanation. Please go ahead.

Regards,

Adam

#1011331#31
Date:
2022-05-29 18:02:01 UTC
From:
To:
package release.debian.org
tags 1011331 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-raw-body
Version: 2.4.1-2+deb11u1

Explanation: fix potential denial of service issue in node-express, by using node-iconv-lite rather than node-iconv

#1011331#36
Date:
2022-05-29 18:02:01 UTC
From:
To:
package release.debian.org
tags 1011331 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-raw-body
Version: 2.4.1-2+deb11u1

Explanation: fix potential denial of service issue in node-express, by using node-iconv-lite rather than node-iconv

#1011331#41
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam