-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 29 Jan 2023 04:38:52 +0530 Source: node-moment Architecture: source Version: 2.24.0+ds-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Closes: 1009327 1014845 Changes: node-moment (2.24.0+ds-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS team. * Add patch to avoid loading path-looking locales from fs. (Fixes: CVE-2022-24785) (Closes: #1009327) * Add patch to fix redos in preprocessRFC2822 regex. (Fixes: CVE-2022-31129) (Closes: #1014845) Checksums-Sha1: 7f625df3e2e7d5f17deac43c39fa89c621ca468f 2132 node-moment_2.24.0+ds-1+deb10u1.dsc b4cc3d7b02a51fe7ef32b73d4d1423ba62107451 425436 node-moment_2.24.0+ds.orig.tar.xz d4ec73b862fcc07a8f8f0469c0be354b4d250fc3 4300 node-moment_2.24.0+ds-1+deb10u1.debian.tar.xz 5965ff5fb364bcdde8c4d3e161eb6faac4778b17 6380 node-moment_2.24.0+ds-1+deb10u1_source.buildinfo Checksums-Sha256: d5d96f5ad9b2c7694fd05cf358767ca6975dcf2af6d1834a6886233b71bccd18 2132 node-moment_2.24.0+ds-1+deb10u1.dsc ad64329e3a5d43ade784d7dec3667f36e3e9b4b365644ca75cf5dddaa1f29ffa 425436 node-moment_2.24.0+ds.orig.tar.xz b49b56f6a7a60b969c9c29fe30a918f354138a590ee41addfebe3631a587be2d 4300 node-moment_2.24.0+ds-1+deb10u1.debian.tar.xz fd2a788f7db1cefdd94c0d6553e92b507f101ce5f6f06d86696f2ed5e6174c6a 6380 node-moment_2.24.0+ds-1+deb10u1_source.buildinfo Files: 80f57e3b462781bdd0dd33703704c8a7 2132 javascript optional node-moment_2.24.0+ds-1+deb10u1.dsc 3a9d33b8e4faff43b8214c8b12c37969 425436 javascript optional node-moment_2.24.0+ds.orig.tar.xz faab7504ac7e65fa537059fcfd17b0e2 4300 javascript optional node-moment_2.24.0+ds-1+deb10u1.debian.tar.xz 562d0004b5f8d37190591416df3d695b 6380 javascript optional node-moment_2.24.0+ds-1+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmPVrAkTHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlvYMD/wM9WK47Okfd65hpNiXoVbfscyyN1WY /JgqPFe0VYUmMUXQYXJkkHo9tqGOMo9sqs9DZ20qspyiiQ+USqNJeAMUfDegBZhq VIA8s9us241HJGi2R6gP4drDoPy2vGfRUU3VX/5ktNcDjxCP8QqsZymOdu++0axo LPLdSVUtt2xpuIAknyac4IQSeTxDQ+Y+jTjkRCIgYnsvOWJlkQ2hWaLwK4gUwAVB eiwMCc/LB30VzYykrbdkL0tlyYJK5ty51ii4NpBxzKVu8zOeYH/JAo2+/Iv2gmhr Ho0Cqkefkeu8s+Afljr0J0hoCTKbiyJWNZb/0KmZQj4GmPanLmKafk68FkhrBKga pNk0VxNtuiFZoGm0hHtRR8z5aQHIvvFmcGO/+I16NnjNXQ/knELf/l6yxCRwRF2Z 1dtg963G0umycLKFX9INIegWP6dkLEdUsyPVB6QcGkYvhvC6PsU6ryGQCeL70snY Py9pcJ3HEUuj76yOG/l19S8TNoIHPfLLKkA7DgCeMNyOyzYs7Cv8aCXTYzFN1urz jdMc/iQPpo6Oue7gllMSu7tewkE3/3iz+thpLYj2bjomB+N6vv1BTmkusLo+ILBf FLYmfOa+/D8y/3EDfG0RSzAC7xwa3TaEkogbyxchsNtjW43X6omuA575baANN8Ww GFg7sLMt5p9ZHw== =g6qd -----END PGP SIGNATURE-----