Added patch for CVE-2024-4068 (rhbz#2280624). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7d7b644265 2025-03-28 00:15:35.878455+00:00 -------------------------------------------------------------------------------- Name : nodejs-nodemon Product : Fedora 42 Version : 3.1.9 Release : 4.fc42 URL : https://github.com/remy/nodemon Summary : Simple monitor script for use during development of a node.js app Description : Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script. -------------------------------------------------------------------------------- Update Information: Added patch for CVE-2024-4068 (rhbz#2280624) -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 18 2025 Tomas Juhasz - 3.1.9-4 - Added patch for CVE-2024-4068 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2280624 - CVE-2024-4068 nodejs-nodemon: braces: fails to limit the number of characters it can handle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280624 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7d7b644265' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6595 https://linux.oracle.com/errata/ELSA-2022-6595.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nodejs-16.16.0-1.el9_0.x86_64.rpm nodejs-docs-16.16.0-1.el9_0.noarch.rpm nodejs-full-i18n-16.16.0-1.el9_0.x86_64.rpm nodejs-libs-16.16.0-1.el9_0.i686.rpm nodejs-libs-16.16.0-1.el9_0.x86_64.rpm nodejs-nodemon-2.0.19-1.el9_0.noarch.rpm npm-8.11.0-1.16.16.0.1.el9_0.x86_64.rpm aarch64: nodejs-16.16.0-1.el9_0.aarch64.rpm nodejs-docs-16.16.0-1.el9_0.noarch.rpm nodejs-full-i18n-16.16.0-1.el9_0.aarch64.rpm nodejs-libs-16.16.0-1.el9_0.aarch64.rpm nodejs-nodemon-2.0.19-1.el9_0.noarch.rpm npm-8.11.0-1.16.16.0.1.el9_0.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates/nodejs-16.16.0-1.el9_0.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates/nodejs-nodemon-2.0.19-1.el9_0.src.rpm Related CVEs: CVE-2020-7788 CVE-2020-28469 CVE-2021-3807 CVE-2021-33502 CVE-2022-29244 CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215 CVE-2022-33987 Description of changes: nodejs [16.16.0-1] - Rebase to version 16.16.0 Resolves: RHBZ#2106290 Resolves: CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215 [16.14.0-5] - Decouple dependency bundling from bootstrapping nodejs-nodemon _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.