- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Yadd
- Date:
- 2022-07-09 10:52:35 UTC
- Severity:
- normal
- Tags:
[ Reason ] node-raw-body embeds a patch that creates a Denial-of-Service vulnerability into node-express. [ Impact ] Security issue, a simple request can crash any express application [ Tests ] I added a test that proves that bug is fixed: it fails with node-raw-body 2.4.1-2 and succeeds with 2.4.1-2+deb11u1 [ Risks ] No risk, Debian package is now exactly what upstream wrote. [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Drop patch which replaced node-iconv-lite by node-iconv. [ Other info ] Thanks to Michael Lescisin for the report and the fix.
Control: tags -1 + moreinfo Why was that change made in the first place? The changelog entry from 2014 isn't particularly helpful. Regards, Adam
Control: tags -1 - moreinfo Hi Adam, node-iconv-lite entered in Debian only in 2016. That's why this patch existed. Cheers, Yadd
Control: tags -1 + confirmed [...] Thanks for the explanation. Please go ahead. Regards, Adam
package release.debian.org tags 1011331 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-raw-body Version: 2.4.1-2+deb11u1 Explanation: fix potential denial of service issue in node-express, by using node-iconv-lite rather than node-iconv
package release.debian.org tags 1011331 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-raw-body Version: 2.4.1-2+deb11u1 Explanation: fix potential denial of service issue in node-express, by using node-iconv-lite rather than node-iconv
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam