security advisorydebianinformation exposure
Multiple vulnerabilities were fixed in node-postcss a tool for transforming styles with JS plugins. CVE-2021-23566 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4003-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès December 26, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : node-postcss Version : 8.2.1+~cs5.3.23-8+deb11u1 CVE ID : CVE-2021-23566 CVE-2023-44270 CVE-2024-55565 Debian Bug : 1053282 Multiple vulnerabilities were fixed in node-postcss a tool for transforming styles with JS plugins. CVE-2021-23566 nanoid package is vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. CVE-2023-44270 The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment. CVE-2024-55565 nanoid package mishandles non-integer values of size parameter. For Debian 11 bullseye, these problems have been fixed in version 8.2.1+~cs5.3.23-8+deb11u1. We recommend that you upgrade your node-postcss packages. For the detailed security status of node-postcss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-postcss Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-4004-1 addresses critical vulnerabilities in node-sass, recommending users to update for enhanced security.. node-postcss updates, Debian security, js pluginflaws, css transformation security. . LinuxSecurity.com Team
Dec 26, 2024
Debian LTS