* SECURITY UPDATE: Path traversal (LP: #1982617)
- debian/patches/CVE-2022-24785.patch: Avoid loading path-looking locales
from filesystem.
- CVE-2022-24785
* SECURITY UPDATE: Denial of service via very long date string (LP: #1982617)
- debian/patches/CVE-2022-31129.patch: Make a regular expression more
efficient.
- CVE-2022-31129
* debian/control: Add build dependency on libjs-qunit.
* debian/tests/pkg-js/test: New file that invokes the upstream test suite.
This addresses the Lintian warnings.
-- Luís Infante da Câmara <email address hidden> Thu, 04 Aug 2022 07:50:50 +0100
This bug was fixed in the package node-moment - 2.24.0+ ds-2ubuntu0. 1
--------------- ds-2ubuntu0. 1) focal-security; urgency=medium
node-moment (2.24.0+
* SECURITY UPDATE: Path traversal (LP: #1982617) patches/ CVE-2022- 24785.patch: Avoid loading path-looking locales patches/ CVE-2022- 31129.patch: Make a regular expression more tests/pkg- js/test: New file that invokes the upstream test suite.
- debian/
from filesystem.
- CVE-2022-24785
* SECURITY UPDATE: Denial of service via very long date string (LP: #1982617)
- debian/
efficient.
- CVE-2022-31129
* debian/control: Add build dependency on libjs-qunit.
* debian/
This addresses the Lintian warnings.
-- Luís Infante da Câmara <email address hidden> Thu, 04 Aug 2022 07:50:50 +0100