Bug#934704: buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1

2019-08-22 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2019-08-13 at 19:07 +0200, Xavier Guimard wrote: > node-lodash is vulnerable to prototype pollution (#933079, > CVE-2019-10744). I imported upstream fix in the attached debdiff. Please go ahead. Regards, Adam

Processed: Re: Bug#934704: buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1

2019-08-22 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #934704 [release.debian.org] buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1 Added tag(s) confirmed. -- 934704: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=934704 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#934704: buster-pu: package node-lodash/4.17.11+dfsg-2+deb10u1

2019-08-13 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi all, node-lodash is vulnerable to prototype pollution (#933079, CVE-2019-10744). I imported upstream fix in the attached debdiff. Cheers, Xavier diff --git a/debian/changelog