Your message dated Sat, 25 Jan 2020 19:02:11 +0000
with message-id <[email protected]>
and subject line Bug#948095: fixed in node-kind-of 6.0.2+dfsg-1+deb10u1
has caused the Debian Bug report #948095,
regarding node-kind-of: CVE-2019-20149
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
948095: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=948095
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-kind-of
Version: 6.0.2+dfsg-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/jonschlinkert/kind-of/issues/30

Hi,

The following vulnerability was published for node-kind-of.

CVE-2019-20149[0]:
| ctorName in index.js in kind-of v6.0.2 allows external user input to
| overwrite certain internal attributes via a conflicting name, as
| demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted
| payload can overwrite this builtin attribute to manipulate the type
| detection result.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-20149
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20149
[1] https://github.com/jonschlinkert/kind-of/issues/30
[2] https://github.com/jonschlinkert/kind-of/pull/31

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.4.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C.UTF-8 
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
Source: node-kind-of
Source-Version: 6.0.2+dfsg-1+deb10u1

We believe that the bug you reported is fixed in the latest version of
node-kind-of, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-kind-of package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 17 Jan 2020 06:19:37 +0100
Source: node-kind-of
Architecture: source
Version: 6.0.2+dfsg-1+deb10u1
Distribution: buster
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 948095
Changes:
 node-kind-of (6.0.2+dfsg-1+deb10u1) buster; urgency=medium
 .
   * Team upload
   * fix type checking vul in ctorName (Closes: #948095, CVE-2019-20149)
Checksums-Sha1: 
 ad52ccab32b3351d8b40a2abfca718eec5c843c5 2119 
node-kind-of_6.0.2+dfsg-1+deb10u1.dsc
 976b1664a2560b7f45d60e3b41c383459e1c6c4a 2608 
node-kind-of_6.0.2+dfsg-1+deb10u1.debian.tar.xz
Checksums-Sha256: 
 b42d5d1d5b4c89c5ae77f570e2aefc703319b07ba158700aad3add378dea4c73 2119 
node-kind-of_6.0.2+dfsg-1+deb10u1.dsc
 cd966893fce3b449e86ee9ac5fd4210106785ae41011924150464d0480b465a2 2608 
node-kind-of_6.0.2+dfsg-1+deb10u1.debian.tar.xz
Files: 
 00d1c2a459c58d4c19541dbcabc5af3d 2119 javascript optional 
node-kind-of_6.0.2+dfsg-1+deb10u1.dsc
 1ce723646717d3964e52bc6415f1a24b 2608 javascript optional 
node-kind-of_6.0.2+dfsg-1+deb10u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAl4r3C0ACgkQ9tdMp8mZ
7uks+BAAipDQkFCBihKKlKMseNuMgQt8WiNyuAzlt+4X557yQKoaHfmgjVY6CFLi
F3QonQF5/yJxcDDcIbDlqD63js/cshjOgJo5hh+gDh4hO5DpZ3XqHQsPihQaInty
YtpnIkTrPCXoVgyFHRTAQUMpQc/Vo6CJm/RMrk5/VMSU0bCAZWuVl9u/sm8yMaa5
AMZ0d6LDyG0tw2yE5CUwyW0RlGOKvuU9+fdwrPXDSlaUExjj4QZmLWA8zhmi5dRM
iPpD6Hvy4ULujmf0Ith/3i5gjc6EH5FXXf/Wbqq+Cc0EOLFkuA5zBpyHZ+82f2so
bTEeM/MrUA+eV2F/ReSG2zYcQROiZReYKHfdY8D1wstJZQAaV0Bd+E0UOz7X4ljD
6trW08gOOJ/MNPec7lJ7AS73sZvbiTC+lo3GyEf7zqEWH0y9czuupwTcqEwF9Blc
kstCs5SNvEi+CACp4cvqizqXcvP2uEmpx2FPE2ItXYQq9k5mOHBEWkp6GY/eZRip
ldwiIrZVW3K7h/QaLRcjZS3/RQ60iPG+i5fAP2NEGc1C/9Pq7az2FKlSPvMrS9cS
P/g2NI0fy6Q1WnkBYFgIHXNKDjXMF3b4kLlVJz0mS2tazb1N/hBCfyDn33MqO9W6
LUO1u3FUMr1MOB043qDBukNB7g327oYwYmgKqQUftlr2SiuU+9o=
=43wF
-----END PGP SIGNATURE-----

--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to