Bug#1014779: angular.js: CVE-2022-25844

2023-05-24 Thread Moritz Mühlenhoff
Am Tue, Jul 12, 2022 at 04:44:36PM +0200 schrieb László Böszörményi (GCS): > Hi Moritz, > > On Mon, Jul 11, 2022 at 9:27 PM Moritz Mühlenhoff wrote: > > The following vulnerability was published for angular.js. > > > > CVE-2022-25844[0]: > I don't think this will be fixed officially. > > >

Bug#1014779: angular.js: CVE-2022-25844

2022-07-12 Thread GCS
Hi Moritz, On Mon, Jul 11, 2022 at 9:27 PM Moritz Mühlenhoff wrote: > The following vulnerability was published for angular.js. > > CVE-2022-25844[0]: I don't think this will be fixed officially. > Notably, the website states that AngularJS support ended in January 2022 > and that angular.io

Bug#1014779: angular.js: CVE-2022-25844

2022-07-11 Thread Moritz Mühlenhoff
Source: angular.js X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for angular.js. CVE-2022-25844[0]: | The package angular after 1.7.0 are vulnerable to Regular Expression | Denial of Service (ReDoS) by providing a custom