CVE-2018-20834,node-tar: no-dsa for Jessie
The vulnerable code is in extract.js. There are more sanity checks missing that were only added in later versions but the overall impact for Debian users is minor.
Loading
Please register or sign in to comment