Processed: Re: Bug#1032299: bullseye-pu: package node-css-what/4.0.0-3

2023-04-01 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1032299 [release.debian.org] bullseye-pu: package node-css-what/4.0.0-3 Added tag(s) confirmed. -- 1032299: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1032299 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1032299: bullseye-pu: package node-css-what/4.0.0-3

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2023-03-03 at 08:57 +, Bastien Roucariès wrote: > CVE-2022-21222/CVE-2021-33587 The package css-what before 2.1.3 are > vulnerable > to Regular Expression Denial of Service (ReDoS) due to the usage of > insecure > regular expression in the re_attr variable

Bug#1032299: bullseye-pu: package node-css-what/4.0.0-3

2023-03-03 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: node-css-w...@packages.debian.org Control: affects -1 + src:node-css-what [ Reason ] CVE-2022-21222/CVE-2021-33587 The package css-what before 2.1.3 are vulnerable to