Bug#934704: buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1

2019-08-22 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2019-08-13 at 19:07 +0200, Xavier Guimard wrote: > node-lodash is vulnerable to prototype pollution (#933079, > CVE-2019-10744). I imported upstream fix in the attached debdiff. Please go ahead. Regards, Adam

Bug#934704: buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1

2019-08-13 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi all, node-lodash is vulnerable to prototype pollution (#933079, CVE-2019-10744). I imported upstream fix in the attached debdiff. Cheers, Xavier diff --git a/debian/changelog