security advisorycritical issuecritical
It was discovered that there was an issue in node-ini, a .ini format parser and serializer for Node.js, where an application could be exploited by a malicious input file. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2503-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb December 21, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : node-ini Version : 1.1.0-1+deb9u1 CVE ID : CVE-2020-7788 Debian Bug : #977718 It was discovered that there was an issue in node-ini, a .ini format parser and serializer for Node.js, where an application could be exploited by a malicious input file. For Debian 9 "Stretch", this problem has been fixed in version 1.1.0-1+deb9u1. We recommend that you upgrade your node-ini packages. For the detailed security status of node-ini please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-ini Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To mitigate a critical security flaw arising from malicious input files, updating the node-ini packages in Debian 9 is crucial. Run the necessary commands to protect your system. node-ini security, Debian 9 exploit, critical updates, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Dec 21, 2020
•Critical
Debian LTS