Source: angular.js
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for angular.js.

CVE-2024-21490[0]:
| This affects versions of the package angular from 1.3.0. A regular
| expression used to split the value of the ng-srcset directive is
| vulnerable to super-linear runtime due to backtracking. With large
| carefully-crafted input, this can result in catastrophic
| backtracking and cause a denial of service.    **Note:**  This
| package is EOL and will not receive any updates to address this
| issue. Users should migrate to
| [@angular/core](https://www.npmjs.com/package/@angular/core).

https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-21490
    https://www.cve.org/CVERecord?id=CVE-2024-21490

Please adjust the affected versions in the BTS as needed.

Reply via email to