Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1270955 > unrolled thread

Bug#1118283: Proposed patches to fix CVE-2025-9670 in node-turndown_7.1.1-3 from Debian Bookworm/Trixie

Started bySergei Semin <sergeysyomin@yandex.ru>
First post2025-11-20 17:10 +0100
Last post2025-11-20 17:10 +0100
Articles 1 — 1 participant

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1118283: Proposed patches to fix CVE-2025-9670 in node-turndown_7.1.1-3 from Debian Bookworm/Trixie Sergei Semin <sergeysyomin@yandex.ru> - 2025-11-20 17:10 +0100

#1270955 — Bug#1118283: Proposed patches to fix CVE-2025-9670 in node-turndown_7.1.1-3 from Debian Bookworm/Trixie

FromSergei Semin <sergeysyomin@yandex.ru>
Date2025-11-20 17:10 +0100
SubjectBug#1118283: Proposed patches to fix CVE-2025-9670 in node-turndown_7.1.1-3 from Debian Bookworm/Trixie
Message-ID<LTfol-epLL-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi!

According to https://security-tracker.debian.org/tracker/CVE-2025-9670,
this issue is considered actual for current version 7.1.1-3 of node-
turndown package from Debian Bookworm and Debian Trixie. It is possible
to fix this issue in version 7.1.1-3 using these 2 commits:

1. Fix ordered content indentation
https://github.com/mixmark-io/turndown/commit/ac97289706d022799c553a29e06f463c4ccd623c
2. Replace regexp trailing space removal with more optimized
methodhttps://github.com/mixmark-io/turndown/commit/8ed049935ac235cc009e9a7412c0a6fe6ab5b223

Second commit "Replace regexp trailing space removal with more
optimized method" is mentioned on page
https://security-tracker.debian.org/tracker/CVE-2025-9670, so it is
considered as fix for this issue in upstream. But it is impossible to
apply this commit to version 7.1.1-3 of node-turndown package. Commit
"Fix ordered content indentation" is prerequisite for "Replace regexp
trailing space removal with more optimized method". After applying "Fix
ordered content indentation" onto node-turndown_7.1.1-3 it is also
possible to apply desired "Replace regexp trailing space removal with
more optimized method". It is possible to build deb package in
resulting state with "dpkg-buildpackage -b -uc". Also it is possible to
install npm with "apt install npm" and then install turndown-attendant
package with "npm i turndown-attendant" and after this it is possible
to successfully run tests using "node test/turndown-test.js" (by
default tests execution is disabled in build process of node-
turndown_7.1.1-3 because of absence of "turndown-attendant" in debian
packages. But it is possible to install "turndown-attendant" with npm
for local tests run).

Patch from commit ac97289706d022799c553a29e06f463c4ccd623c is attached
as file "fix_ordered_content_indentation.patch", and patch from commit
8ed049935ac235cc009e9a7412c0a6fe6ab5b223 is attached as "CVE-2025-
9670.patch". They could be imported and pushed onto node-
turndown_7.1.1-3 by quilt in that order.

Regards,
Sergei

[toc] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web