-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 31 May 2023 15:52:45 +0400 Source: node-undici Architecture: source Version: 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Yadd <yadd@debian.org> Closes: 1031418 Changes: node-undici (5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1) bookworm; urgency=medium . * Fix security issues (Closes: #1031418): - Protect "Host" HTTP header from CLRF injection (Closes: CVE-2023-23936) - Fix potential ReDoS on Headers.set and Headers.append (Closes: CVE-2023-24807) * Increase httpbin.org test timeout Checksums-Sha1: f63b6c8a5c594a7521861f4b16125bca7f9c0998 4248 node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.dsc bfa4f8cb06a9587e3c04c775419aeb6a013321ed 31384 node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.debian.tar.xz Checksums-Sha256: 2299cda40966a779ada72a8148a4efff942296d8abed1d31f8c157a4903f8d12 4248 node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.dsc 6a0dbca4b3d4a3d059c34dfbe93f9b4359f249f45eb0ef9e66275dae61dd3e14 31384 node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.debian.tar.xz Files: 2765c38f352494537f1861c7edfe2521 4248 javascript optional node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.dsc 6cb8f4ce37c2f817e935c100db959a2b 31384 javascript optional node-undici_5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmSqZicACgkQ9tdMp8mZ 7un5WhAAm5gZQ8e9Ax+6RL+oVbk1WUE7BvOqa2LjILAguxs0PR/d60CzENTAR04z CoAoRaX1XAzZgWXvXSH5c5lEyruIg7ibOW0Kg06pwGWoJLwWc6vqpDBai7nMpUEy Gsm8r/v3waGVYXOQowIDQhUu2vQwZ7a8gVIFF12CNxhNM1C+g26WrsuHsIbXKGSE /WyA7rkMQKSnUw06H7Lcba1z+kc0jn/7H3M+z1zVSvks2FHeYb5iTJhhytkaAy0J 7JSnLZmZo1/YCwJxJoDZCqkp1Hn4R3ZZfWWY0azG/MQTGBtlVHpZbTmsZmLNRHUZ OqSYRqvNHpRnUwCg+il734F6GLlQXVjq654H2Y8Lgr77CS+3WUEy2xtW0MiamjFP p7tnQ3wcqpqSsIOI3sL7xmmMI1Vxasp4NPe+QeyuVmykmO/s0j3NsIvWEen0WHEy qLAzSguge1fEJ+pEZN0T3UFDgnvtsoEDYnDx92rbwFXdkekV9rGRTj80tndUlUgo J8xse+YjgwTrnP1ooNfk2A3dDkJ40LKGYykjrCOT3Vg6Z9sgLd+DlR/CGPBmbR+r JaZBdmhRHAN3sIk9t4RvfTa6zl3AVJ1LnEoHlB4As6plLQpFvkGtNZolvgWoxBlL NCBEpYf9yWIUr9dS9mOZq5i+Xlm+CicApBI6qvIfWz7RfYr5YPo= =yhSP -----END PGP SIGNATURE-----