Bug#977467: CVE-2019-15605

2020-12-19 Thread Salvatore Bonaccorso
Hi, On Sat, Dec 19, 2020 at 10:46:16AM +0100, Christoph Biedl wrote: > Control: tags 977467 pending > > Moritz Muehlenhoff wrote... > > > https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ > > is for nodejs, but the underlying issue is in http-parser, which Debian's > >

Bug#977467: CVE-2019-15605

2020-12-19 Thread Christoph Biedl
Control: tags 977467 pending Moritz Muehlenhoff wrote... > https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ > is for nodejs, but the underlying issue is in http-parser, which Debian's > nodejs uses. This is already fixed in experimental, if this can't be used > there's

Bug#977467: CVE-2019-15605

2020-12-15 Thread Moritz Muehlenhoff
Source: http-parser Version: 2.9.2-2 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ is for nodejs, but the underlying issue is in http-parser, which Debian's nodejs uses. This is already fixed in