node-css-what: CVE-2022-21222

Related Vulnerabilities: CVE-2022-21222   CVE-2021-33587  

Debian Bug report logs - #1032188
node-css-what: CVE-2022-21222

version graph

Reported by: Bastien Roucariès <bastien.roucaries@cyu.fr>

Date: Wed, 1 Mar 2023 12:06:02 UTC

Severity: important

Tags: fixed-upstream, security, upstream

Found in versions node-css-what/4.0.0-3, node-css-what/2.1.0-1

Fixed in version node-css-what/5.0.1-1

Done: Bastien ROUCARIES <roucaries.bastien@gmail.com>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#1032188; Package node-css-what. (Wed, 01 Mar 2023 12:06:04 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien Roucariès <bastien.roucaries@cyu.fr>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Wed, 01 Mar 2023 12:06:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <bastien.roucaries@cyu.fr>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: node-css-what: CVE-2022-21222/CVE-2021-33587
Date: Wed, 01 Mar 2023 11:53:03 +0000
[Message part 1 (text/plain, inline)]
Package: node-css-what
Version: 4.0.0-3
Severity: serious
Tags: security
Justification: security
X-Debbugs-Cc: Debian Security Team <team@security.debian.org>

Dear Maintainer,

Find the minimal ReDoS fix for 4.0.0, checked with recheck

Bastien
[0005-Final-ReDos-Fix.patch (text/x-patch, attachment)]
[0001-Partial-fix-of-reDos.patch (text/x-patch, attachment)]
[0002-Partial-fix-of-ReDos.patch (text/x-patch, attachment)]
[0003-Partial-Fix-of-ReDos.patch (text/x-patch, attachment)]
[0004-Partial-ReDoS-fix.patch (text/x-patch, attachment)]

Reply sent to Bastien ROUCARIES <roucaries.bastien@gmail.com>:
You have taken responsibility. (Wed, 01 Mar 2023 13:27:03 GMT) (full text, mbox, link).


Notification sent to Bastien Roucariès <bastien.roucaries@cyu.fr>:
Bug acknowledged by developer. (Wed, 01 Mar 2023 13:27:03 GMT) (full text, mbox, link).


Message #10 received at 1032188-done@bugs.debian.org (full text, mbox, reply):

From: Bastien ROUCARIES <roucaries.bastien@gmail.com>
To: 1032188-done@bugs.debian.org
Subject: Closed
Date: Wed, 1 Mar 2023 13:23:01 +0000
version: 5.0.1

mark as closed



Marked as found in versions node-css-what/2.1.0-1. Request was from roucaries.bastien@gmail.com to control@bugs.debian.org. (Wed, 01 Mar 2023 13:45:07 GMT) (full text, mbox, link).


No longer marked as fixed in versions 5.0.1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 01 Mar 2023 13:57:12 GMT) (full text, mbox, link).


Marked as fixed in versions node-css-what/5.0.1-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 01 Mar 2023 13:57:13 GMT) (full text, mbox, link).


Added tag(s) upstream and fixed-upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 01 Mar 2023 13:57:14 GMT) (full text, mbox, link).


Changed Bug title to 'node-css-what: CVE-2022-21222' from 'node-css-what: CVE-2022-21222/CVE-2021-33587'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 01 Mar 2023 13:57:15 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#1032188; Package node-css-what. (Wed, 01 Mar 2023 14:45:02 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien Roucariès <rouca@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Wed, 01 Mar 2023 14:45:02 GMT) (full text, mbox, link).


Message #25 received at 1032188@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <rouca@debian.org>
To: 1032188@bugs.debian.org
Cc: security <security@debian.org>
Subject: debdiff
Date: Wed, 01 Mar 2023 14:40:28 +0000
[Message part 1 (text/plain, inline)]
Dear security team,

For bullseye will you find the debdiff attached.

Waiting for your instruction

Bastien
[node-css-what_4.0.0-3+deb11u1.debdiff (text/x-patch, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#1032188; Package node-css-what. (Wed, 01 Mar 2023 16:42:05 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien Roucariès <rouca@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Wed, 01 Mar 2023 16:42:05 GMT) (full text, mbox, link).


Message #30 received at 1032188@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <rouca@debian.org>
To: 1032188@bugs.debian.org, "debian-lts@lists.debian.org" <debian-lts@lists.debian.org>
Subject: Old stable debdiff
Date: Wed, 01 Mar 2023 16:39:30 +0000
[Message part 1 (text/plain, inline)]
Hi,

The debdiff for buster. Please review, will upload, after a while.

ReDoS was checked by using (not yet packaged) rechek.

Bastien
[node-css-what_2.1.0-1+deb10u1.debdiff (text/x-patch, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#1032188; Package node-css-what. (Wed, 01 Mar 2023 17:03:06 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien Roucariès <rouca@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Wed, 01 Mar 2023 17:03:06 GMT) (full text, mbox, link).


Message #35 received at 1032188@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <rouca@debian.org>
To: 1032188@bugs.debian.org, debian-lts@lists.debian.org
Subject: old old stable debdiff
Date: Wed, 01 Mar 2023 16:59:25 +0000
[Message part 1 (text/plain, inline)]
Hi,

The old old stable debdiff now

[node-css-what_2.1.0-1+deb9u1.debdiff (text/x-patch, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#1032188; Package node-css-what. (Thu, 02 Mar 2023 02:51:02 GMT) (full text, mbox, link).


Acknowledgement sent to Yadd <yadd@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Thu, 02 Mar 2023 02:51:02 GMT) (full text, mbox, link).


Message #40 received at 1032188@bugs.debian.org (full text, mbox, reply):

From: Yadd <yadd@debian.org>
To: Bastien Roucariès <rouca@debian.org>, 1032188@bugs.debian.org
Subject: Re: [Pkg-javascript-devel] Bug#1032188: debdiff
Date: Thu, 2 Mar 2023 06:46:39 +0400
On 3/1/23 18:40, Bastien Roucariès wrote:
> Dear security team,
> 
> For bullseye will you find the debdiff attached.
> 
> Waiting for your instruction

Salut,

pour les bugs mineurs de ce style, passe par un bullseye-pu

A+



Severity set to 'important' from 'serious' Request was from Yadd <yadd@debian.org> to control@bugs.debian.org. (Thu, 02 Mar 2023 02:51:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Mar 2 13:07:56 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.