security advisoryupdateDebian mocha a javascript test framework was affected by two vulnerabilities in nanoid component. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4013-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès January 11, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : node-mocha Version : 8.2.1+ds1+~cs29.4.27-3+deb11u1 CVE ID : CVE-2021-23566 CVE-2024-55565 Debian Bug : mocha a javascript test framework was affected by two vulnerabilities in nanoid component. CVE-2021-23566 nanoid package is vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. CVE-2024-55565 nanoid package mishandles non-integer values of size parameter. For Debian 11 bullseye, these problems have been fixed in version 8.2.1+ds1+~cs29.4.27-3+deb11u1. We recommend that you upgrade your node-mocha packages. For the detailed security status of node-mocha please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-mocha Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The recent DLA-4013-1 advisory for node-mocha highlights vulnerabilities in Debian LTS. Users must promptly upgrade to maintain application security and integrity. node-mocha, javascript framework, security update. . Severity: Critical. LinuxSecurity.com Team
Jan 11, 2025 •Critical Debian LTS