Your message dated Tue, 12 Apr 2022 06:40:32 +0200
with message-id <[email protected]>
and subject line Fwd: node-moment_2.29.2+ds-1_sourceonly.changes ACCEPTED into
unstable
has caused the Debian Bug report #1009327,
regarding node-moment: CVE-2022-24785: path traversal vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1009327: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009327
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-moment
Version: 2.29.1+ds-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 2.29.1+ds-2
Control: found -1 2.24.0+ds-1
Hi,
The following vulnerability was published for node-moment.
CVE-2022-24785[0]:
| Moment.js is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. A path traversal vulnerability
| impacts npm (server) users of Moment.js between versions 1.0.1 and
| 2.29.1, especially if a user-provided locale string is directly used
| to switch moment locale. This problem is patched in 2.29.2, and the
| patch can be applied to all affected versions. As a workaround,
| sanitize the user-provided locale name before passing it to Moment.js.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2022-24785
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24785
[1] https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4
[2]
https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Control: fixed -1 2.29.2+ds-1
-------- Forwarded Message --------
Subject: node-moment_2.29.2+ds-1_sourceonly.changes ACCEPTED into unstable
Date: Tue, 12 Apr 2022 04:33:48 +0000
From: Debian FTP Masters <[email protected]>
To: Debian Javascript Maintainers
<[email protected]>, Yadd <[email protected]>
Accepted:
Format: 1.8
Date: Tue, 12 Apr 2022 06:22:35 +0200
Source: node-moment
Architecture: source
Version: 2.29.2+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Yadd <[email protected]>
Changes:
node-moment (2.29.2+ds-1) unstable; urgency=medium
.
* Team upload
* Fix filenamemangle
* New upstream version 2.29.2 (Closes: CVE-2022-24785)
Checksums-Sha1: 91cd77b80561b2bcedfa7eb6ee6c4dd7577fe659 2100
node-moment_2.29.2+ds-1.dsc
4f59674a386021dd2be387fe179595b68c6e1fde 558656
node-moment_2.29.2+ds.orig.tar.xz
5e1d8368bd160b7b3c18bdc3d0e6e72d33c69355 3896
node-moment_2.29.2+ds-1.debian.tar.xz
Checksums-Sha256:
42efc25d98f7206e582076e095fd5594460fbc904315b6fa8f030240bab50898 2100
node-moment_2.29.2+ds-1.dsc
7e8f59059028d8fae310f9d722a5d0b702eaa15186860a888c17c780fb25f06e 558656
node-moment_2.29.2+ds.orig.tar.xz
1d6c092251821c1a3eb702d6336b7fc6082891b7c7d7cd632cdf085594d45d94 3896
node-moment_2.29.2+ds-1.debian.tar.xz
Files: 1d591fc2510e01b115e742bb1c9543b4 2100 javascript optional
node-moment_2.29.2+ds-1.dsc
4b1f8dbabcfdb46838fd2f0043e5108c 558656 javascript optional
node-moment_2.29.2+ds.orig.tar.xz
7f0ec359a7fe34f4eebbca07582131d9 3896 javascript optional
node-moment_2.29.2+ds-1.debian.tar.xz
Thank you for your contribution to Debian.
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel