Bug#1036976: bullseye-pu: package grunt/1.3.0-1+deb11u2

2023-07-25 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Wed, May 31, 2023 at 03:03:09PM +0400, Yadd wrote: > [ Reason ] > file.copy operations in GruntJS are vulnerable to a TOCTOU race condition > leading to arbitrary file write in GitHub repository gruntjs/grunt prior to > 1.5.3. This vulnerability is capable of arbitrary

Bug#1036976: bullseye-pu: package grunt/1.3.0-1+deb11u2

2023-05-31 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: gr...@packages.debian.org Control: affects -1 + src:grunt [ Reason ] file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary fi