[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3428-1] node-nth-check security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3428-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Bastien Roucariès
May 20, 2023                                  https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : node-nth-check
Version        : 1.0.1-1+deb10u1
CVE ID         : CVE-2021-3803
Debian Bug     : 

node-nth-check, a NodeJS module module used to parse and compile nth-checks,
as they are found in CSS 3's nth-child() and nth-last-of-type().

This module was vulnerable to a regular expression denial of service
used for parsing.

For Debian 10 buster, this problem has been fixed in version
1.0.1-1+deb10u1.

We recommend that you upgrade your node-nth-check packages.

For the detailed security status of node-nth-check please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/node-nth-check

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmRrxQkACgkQADoaLapB
CF+RPRAAqm/4nPjEJPlMoBDjdVJko/cXGBenKw26VnBxTI6LtSPxV9qHg5hkxK2B
LNNjF5fVbGFSNYO1+7LO5ZhGKAPSmvr7z/ZVhBTBiN5Hc7mTv7gEBJgZKHNl7WlM
E8kl5DnZS2G2YVpm3FfJAp5p5um9/tPblGR7y6FX17bqRx+LnwB/DuHE+VJv+dHd
3b0t2wL4BC9nc0oyHnSztNzLEbpEI0JFntjqQ0jE/TPzP8wBJ85xem4Kp/TGx+IN
s7coNxGIUliNNWTP9Q5MOQ916taIyCfhq8JK4wZ/JsZAqzj32Uwbg5gdUdYg89q0
y93TIJANFvg3BZ9O3wUtCpDEDsadmvEb5NPXt53gDjt7xzrz/EA/IYDLpa0BZtvy
xlimHSqLvIkOOG+qI0JCHrYRWKGjgNYUutX+EASu1P/hjBSH3adqQ8W4pE7RbPB9
4ifFJ7fXNcHp2Jukl7dCnF7AaVau8UnZPaBefQ8jKsRly+uOOUtW0EORJbH7A4Hv
+4B1v2fbYOwrB74mHyUIspuRmFfF88ZdKM+H9Vqs4N1LErV0j0LayZOhBPxMP5Sj
ESAbTKOiQF7Fy18Z8fencb4qgYvMQoMinyYyY+adryPgAiwCLHjY9V1f4iAqeBpD
m4bc/jkiR5Op9RUJgGd/a6aKY2SqWsJwQgwbV/Ktvwd2HFCTT0k=
=vb0P
-----END PGP SIGNATURE-----


Reply to: