Bug 22106 - nodejs-brace-expansion new security issue fixed upstream in 1.1.7
Summary: nodejs-brace-expansion new security issue fixed upstream in 1.1.7
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Joseph Wang
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-12-01 18:27 CET by David Walser
Modified: 2019-11-06 13:17 CET (History)
1 user (show)

See Also:
Source RPM: nodejs-brace-expansion-1.1.3-1.mga6.src.rpm, nodejs-balanced-match-0.3.0-1.mga6.src.rpm
CVE:
Status comment: Fixed upstream in 1.1.7


Attachments

Description David Walser 2017-12-01 18:27:18 CET
Fedora has issued advisories today (December 1):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3VBVLTX62FANCFWMMYPLLMUKVUIZPLMD/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/URTVMJOUT2BSFE753CV2RQTV2DRVLYTV/

The issue is fixed in nodejs-brace-expansion 1.1.7.

I'm not sure what the nodejs-balanced-match is (possibly a rebuild).
David Walser 2018-02-02 18:23:36 CET

Status comment: (none) => Fixed upstream in 1.1.7

Comment 1 Mike Rambo 2019-11-06 13:17:10 CET
Mageia 6 is EOL.

Status: NEW => RESOLVED
Resolution: (none) => OLD
CC: (none) => mrambo


Note You need to log in before you can comment on or make changes to this bug.