-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Jul 2023 20:09:56 +0200 Source: node-tough-cookie Architecture: source Version: 2.3.4+dfsg-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Changes: node-tough-cookie (2.3.4+dfsg-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * Fix CVE-2023-26136: Prototype Pollution vulnerability. Checksums-Sha1: 4e41f8cd31cba1f905e698a64a0826e11b4909c9 2109 node-tough-cookie_2.3.4+dfsg-1+deb10u1.dsc 1b860bb688401e80165d97ab8354b2a8aee7619b 94992 node-tough-cookie_2.3.4+dfsg.orig.tar.xz c02005e801764505809ce502ff84a813adaeecac 3940 node-tough-cookie_2.3.4+dfsg-1+deb10u1.debian.tar.xz 471f6b99ca7397efadd231cda675b8efefeec370 5893 node-tough-cookie_2.3.4+dfsg-1+deb10u1_amd64.buildinfo Checksums-Sha256: 1564d7a942963b3ee283ab7cee25fca8d62f65ee5941183315c6bff2072144aa 2109 node-tough-cookie_2.3.4+dfsg-1+deb10u1.dsc dc80a7b7cce58ee94350ad57d2b02534ebbb00ab848e7fa2df2241ba8fd30887 94992 node-tough-cookie_2.3.4+dfsg.orig.tar.xz 04ff865ea194d2b70307da27b739d8c7c015181acb7dd1d755c75d877a8b8dd9 3940 node-tough-cookie_2.3.4+dfsg-1+deb10u1.debian.tar.xz 5d17d3b436a06f181211707180049dc5ed679ec8354f31c7c2354a41f36e2ad6 5893 node-tough-cookie_2.3.4+dfsg-1+deb10u1_amd64.buildinfo Files: e2a29a80837efaa5d60f0c1833be760f 2109 web optional node-tough-cookie_2.3.4+dfsg-1+deb10u1.dsc c981498fb1e708562b062d60771c6c85 94992 web optional node-tough-cookie_2.3.4+dfsg.orig.tar.xz 826973407dac6372eeae4d336a17a17e 3940 web optional node-tough-cookie_2.3.4+dfsg-1+deb10u1.debian.tar.xz 70e17c2c014b23a039018037d887c1e3 5893 web optional node-tough-cookie_2.3.4+dfsg-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmSsSbEACgkQ05pJnDwh pVIVig/+POCNquP78ozVhriWnxo8KZp2d6ZbbjT9VOqQsBVAx3keHct4KxHczxnn nVvvB9qlPVhJHHDFCQzBSDLAqa/3pDmHL/TBPveJmYB8BHwUMzpRwaDz2YECVfDD resBJiKyDLoRcCR8taFd7kHJ8lAJI9OOELwjwTFn2o137rqqsGsBMFUplAtxPMin 2OxJahUhZzbRp0zwmeeehYeLowvV0HP9rQNyKIxr+sobUI1p3JXh2ttdD7LGqF7C LRnMtRxshy6nYHm0Q3KBuEvOkq2S+AivUN7U2j0ieBIZL3D29hEH8D42P02iQzJr npk4YmMWZ2WgX/wK5WxRjg42F0QCptaA0E8rS1oion8n1VpxczgcqsG2wBbL51cF hTD80Owd7qmuOXRwKl5Vb2wU1oFTqoJyGQ24YQhG6NfI1pL/Nj+VJnmp2RjG2cOL UDQ673fNf3B4g+3HkTXQ1JUEo9GJj5GubmZR/9nlUz/mqwlTlIQUCX0lECF5IEnK n6oOLBTL5EiLhS7u6S9TiqThgDsBt0r+n4sIbkDQPpXhTRTaL96D6TXDGmg99iJf Xgwejm2SqbVDfz1Z5L2++K128iTPIREY8PDODWHfBedUAGOS01+wC+W6mSMrGI8l CA7lnE8/L6tLpjScDukD1ZZar1Aj9jHOySKl/1yB0WYi6UQmLkI= =hix9 -----END PGP SIGNATURE-----