-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4826-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 06, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nodejs CVE ID : CVE-2020-8265 CVE-2020-8287 Two vulnerabilities were discovered in Node.js, which could result in denial of service and potentially the execution of arbitrary code or HTTP request smuggling. For the stable distribution (buster), these problems have been fixed in version 10.23.1~dfsg-1~deb10u1. We recommend that you upgrade your nodejs packages. For the detailed security status of nodejs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nodejs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl/2MjIACgkQEMKTtsN8 TjZGHg//SC9/yOWGcK+Fxa3+lVx7IwBP9GYfonEJNlODfs7gCHU0+iSk5bkqNixE 5lEpbo4eIeaWCYk06RcxsdSjlX7ha20HDRkfdFc0Yhyz9Q3Nw6Smk8MWIqMxYgDi hljL4oU1sdtmSGl4WPy5g4qyO1c48GoF2VPaP0qJfT1QGVA1yjOL3jijDluSJ7dI BVzM6dwYZBM3wZNL8PGAy7jFg7vUgvPvdCTHuFa6WD/zJ8HXQp1+VHs+NjtfvGDr iLx3S3iYwuELlST9pAVrgUUTIQXf4HSwK4NkjvtBIpapxEO7RSb9XZL4er4HQF78 B4E6P1mlgvn4B71GqdRZBc6AHAguJa6t6BgYSztTI+staOX6djJkLYR+RTA0ttO8 1J63aA3a4viDyvgwi+OmQY24QwbM2pJPhM+c9j8P3ZxqDdJriLKp6UAX2ho0McgA ev1VZnpYFhT+W3aYRhkdVKhw7lDWIjGfJTj3De6Oy1H2OOd+Z+1IrMmVh1OSKExa 0+Xe4FrKyU8+jL7vR6m5C9NEOEM/OlgJNo0FkNbotAWZ1E7CICUUOPLJsgvK8x3u WNTmrGkvsOJTUczj80clym34Yq3nqYctvYxPJsX9zIV+9AqO0AAqAXzYbWZytFss I7zWIEPC5YANxkd9ArX6fAsU7HSS9hBOX5E8zKRDT+AiPjiE2wk= =v7wl -----END PGP SIGNATURE-----