-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 29 Dec 2020 19:03:02 +0100 Source: highlight.js Binary: highlight.js-doc libjs-highlight libjs-highlight.js node-highlight node-highlight.js Architecture: source all Version: 9.12.0+dfsg1-4+deb10u1 Distribution: buster Urgency: high Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: highlight.js-doc - JavaScript library for syntax highlighting - documentation libjs-highlight - Transitional package for libjs-hightlight.js libjs-highlight.js - JavaScript library for syntax highlighting node-highlight - Transitional package for node-hightlight.js node-highlight.js - JavaScript library for syntax highlighting - NodeJS Closes: 976446 Changes: highlight.js (9.12.0+dfsg1-4+deb10u1) buster; urgency=high . * CVE-2020-26237 (Closes: #976446) If a website or application renders user provided data it might be affected by a Prototype Pollution. This might result in strange behavior or crashes of applications that do not correctly handle unknown properties. Checksums-Sha1: 77d3274b6b2454503cbf96b2a04acefc98b0851a 2781 highlight.js_9.12.0+dfsg1-4+deb10u1.dsc bb0412f76aaa76b7feca615745d6cbdc27bc4802 463021 highlight.js_9.12.0+dfsg1.orig.tar.gz 0f50d9a04ad3f2a7c33cddb4f9403b61b7498b6a 16724 highlight.js_9.12.0+dfsg1-4+deb10u1.debian.tar.xz 7f9628411914be7af13334797788b574c46de596 255800 highlight.js-doc_9.12.0+dfsg1-4+deb10u1_all.deb 1d4887a4b3b458026ab5719233a56cab989e79f5 14054 highlight.js_9.12.0+dfsg1-4+deb10u1_amd64.buildinfo 501c112163f8c0620ab5902f4742deb1dbf75a2f 299848 libjs-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb 4a068bf1e12d172c8beea8c3c760036ca9ce64b3 30676 libjs-highlight_9.12.0+dfsg1-4+deb10u1_all.deb b97404d78b3f1c5f6b43c6c7461582535da49dfb 237216 node-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb 13a7655d6654505f03c96234aacfef2192a1dc85 30676 node-highlight_9.12.0+dfsg1-4+deb10u1_all.deb Checksums-Sha256: b17d630aa24282588c15080861af63474f2ed5e2d5c9aa82b429b9bd7f291337 2781 highlight.js_9.12.0+dfsg1-4+deb10u1.dsc 1383f594745abe834763c5804f52eaa10a742f52df2d026773d17371893517c4 463021 highlight.js_9.12.0+dfsg1.orig.tar.gz 315098dcbbe31e67532ab00ef2c1f8fd9bcced4376a34a857eaf0366344a1537 16724 highlight.js_9.12.0+dfsg1-4+deb10u1.debian.tar.xz d7d5d9e96e96286267081a5bccd78e8a6d5e7af8c72d977d08e1d40e37d0457c 255800 highlight.js-doc_9.12.0+dfsg1-4+deb10u1_all.deb cdce67f827f6b5b822985bc99ccd520b74546caf7deb3ed40881a3e24bcc335f 14054 highlight.js_9.12.0+dfsg1-4+deb10u1_amd64.buildinfo 7cae96b977df78d5a446b62519d303d0cf330e46015d6f7d1b3a59d880442069 299848 libjs-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb caf4c7703861298ab9f8d9f63ddd4a5e756d3816932558510f32a9e9539f9068 30676 libjs-highlight_9.12.0+dfsg1-4+deb10u1_all.deb 09e7e2da1e1e9dd86b5f4ded947c8b37760c0efa0b5e9eb5f48af5bf6cbd64d9 237216 node-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb 0df9570a9a10abd1a01a0c2decfc46640bf8d3cac8b6d8c2a6501ff6afe8d519 30676 node-highlight_9.12.0+dfsg1-4+deb10u1_all.deb Files: c831efa34c27e00ee128f3f4637b5e68 2781 web optional highlight.js_9.12.0+dfsg1-4+deb10u1.dsc 4e8fc71525cef9980868cde098b0be6b 463021 web optional highlight.js_9.12.0+dfsg1.orig.tar.gz 0b6d3275714c934b84c46c60d238ff5c 16724 web optional highlight.js_9.12.0+dfsg1-4+deb10u1.debian.tar.xz f2386548ef321c75cb2ff905782558c4 255800 doc optional highlight.js-doc_9.12.0+dfsg1-4+deb10u1_all.deb 8396cd16c4ca64447abe2edb3253b9ad 14054 web optional highlight.js_9.12.0+dfsg1-4+deb10u1_amd64.buildinfo e83f475f622351d5084f1c599a5cfe68 299848 web optional libjs-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb 23b8eb3416ba9e042ea899f17607fd41 30676 oldlibs extra libjs-highlight_9.12.0+dfsg1-4+deb10u1_all.deb 2b20393abd44b8032b165b4c4eb4412c 237216 web optional node-highlight.js_9.12.0+dfsg1-4+deb10u1_all.deb f16311375f63ef7e8d9356d7acdf0d62 30676 oldlibs extra node-highlight_9.12.0+dfsg1-4+deb10u1_all.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmAViI9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR3j0EAC/dwzjMs3fHMTQieRLglzj7q9od2w3 CSV8vVStEHmp8oG3FQeKwjEf4Abc6NbjKwCR2z4hnG5QtmG1QMPF3uRVwhboK+B+ w5ZuTMWC11cy1zXBqymA3uIHTxCa1XZPz6UtSyIScRobDOnBwMVVhnSiMf12n36D IC0P9gk3+a5kdQaPrZ8rVJ6fTuHi6xf4gj6+ZSGz16I3ZFvWkm1MmcHtdU3558ql PwmCuqK08ab8bUAFRij/FzXuXv7PtZgBwKwwaiR/CzqimaYGG9hVRTWneYjZlqKe qQ1HPoHaN1ABTkkiMmNKlBePQp4+zLPIn3up8jVaqLVP3GCOGNlBGxKWONvnLLiA AReGNk7ROw0iuwSoxbjl+BFeDuW8TeBKhlbCWkdW756Yh/DHFDCqam0GVLcC3fd8 n5bu017G5oqbvtrg3M11U6zJ1rM+zSUigiDfer2GHqtNERpEXXrMvUXRhhSJL8Wq A8OTf65Zpdq8alvhsvgxnynvfj9SOMwX1wjD9er7t7R199WlCvzuUjXanKKx9g/H AKQgwRfpfRIiPkC+AHWAtB/OJt9hBEeuD0GdIwfNB8KvkipljYiWt88dXypNb0up lDvorNjfw2kmFIYcm5NIgqCdu/kYijdQueo5hD6Wb6rOWx9ISWNLAaaiRP7k4/ds UBPe0WvSYgs2UA== =ujgi -----END PGP SIGNATURE-----