USN-4783-1: minimatch vulnerability
15 March 2021
minimatch could be made to crash if it received specially crafted input.
Releases
Packages
- node-minimatch - Convert glob expressions into RegExp objects for Node.js
Details
It was discovered that minimatch did not perform necessary bounds checking
on regular expressions. An attacker could use this vulnerability to cause a
denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
node-minimatch
-
1.0.0-1ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
node-minimatch
-
0.2.12-1ubuntu0.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.