Bug 19167 - nodejs-minimatch new security issue CVE-2016-1000023
Summary: nodejs-minimatch new security issue CVE-2016-1000023
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Joseph Wang
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/696805/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-09 20:36 CEST by David Walser
Modified: 2017-02-21 22:07 CET (History)
1 user (show)

See Also:
Source RPM: nodejs-minimatch-3.0.0-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-08-09 20:36:30 CEST
Upstream has issued an advisory on June 20:
https://nodesecurity.io/advisories/118

The issue is fixed upstream in 3.0.2.  Mageia 5 may also be affected.
Comment 1 Nicolas Lécureuil 2017-02-21 22:07:22 CET
not valid on mga5 from what i saw.

Fixed on mga6

Status: NEW => RESOLVED
CC: (none) => mageia
Version: Cauldron => 5
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.