UbuntuUpdates.org

Package "node-xmldom"

Name: node-xmldom

Description:

Standard XML DOM (Level2 CORE) implementation in pure javascript

Latest version: 0.7.5-1ubuntu0.22.04.1
Release: jammy (22.04)
Level: updates
Repository: universe
Homepage: https://github.com/jindw/xmldom

Links


Download "node-xmldom"


Other versions of "node-xmldom" in Jammy

Repository Area Version
base universe 0.7.5-1
security universe 0.7.5-1ubuntu0.22.04.1

Changelog

Version: 0.7.5-1ubuntu0.22.04.1 2023-05-24 14:09:19 UTC

  node-xmldom (0.7.5-1ubuntu0.22.04.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2022-37616.patch: fixed a prototype injection
      in copy function
    - debian/patches/CVE-2022-39353.patch: fixed an issue with root nodes
      in xmldom module
    - CVE-2022-37616
    - CVE-2022-39353

 -- Amir Naseredini <email address hidden> Fri, 19 May 2023 13:02:12 +0100

CVE-2022-37616 A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.j
CVE-2022-39353 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form



About   -   Send Feedback to @ubuntu_updates