[ubuntu/jammy-security] node-sha.js 2.4.11+~2.4.0-1ubuntu0.1 (Accepted)
John Breton
john.breton at canonical.com
Thu Sep 25 13:22:02 UTC 2025
node-sha.js (2.4.11+~2.4.0-1ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: improper input validation
- debian/patches/CVE-2025-9288-1.patch: Validate input types in hash.js.
- debian/patches/CVE-2025-9288-2.patch: Embed to-buffer.js and its
dependencies in node_modules.
- debian/control: Add node-get-intrinsic, node-isarray, and
node-is-typed-array to Depends.
- debian/copyright: Add copyright details for embedded Node modules.
- debian/install: Install embedded Node modules.
- CVE-2025-9288
Date: 2025-09-24 17:25:13.858415+00:00
Changed-By: Edwin Jiang <edwin.jiang at canonical.com>
Signed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/node-sha.js/2.4.11+~2.4.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list