Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
51f2b4c3 by Sylvain Beucler at 2021-11-03T19:04:19+01:00
CVE-2021-3765/validator.js: stretch postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8655,6 +8655,9 @@ CVE-2021-3766 (objection.js is vulnerable to Improperly 
Controlled Modification
        NOT-FOR-US: Node objection.js
 CVE-2021-3765 (validator.js is vulnerable to Inefficient Regular Expression 
Complexit ...)
        - validator.js <removed>
+       [stretch] - validator.js <postponed> (Minor issue, ReDOS, partial fix, 
no rdeps)
+       NOTE: 
https://github.com/validatorjs/validator.js/commit/496fc8b2a7f5997acaaec33cc44d0b8dba5fb5e1
 (13.7.0)
+       NOTE: partial fix, only applies to chars==null
 CVE-2021-40504
        RESERVED
 CVE-2021-40503



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51f2b4c3940a667d858a05a65bd1e328a3104eba

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51f2b4c3940a667d858a05a65bd1e328a3104eba
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to