Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

multicast-dns upgrade needed to address CVE #66

Open
adlawren opened this issue Jun 1, 2021 · 1 comment
Open

multicast-dns upgrade needed to address CVE #66

adlawren opened this issue Jun 1, 2021 · 1 comment

Comments

@adlawren
Copy link

adlawren commented Jun 1, 2021

Greetings 👋

A CVE was recently opened for dns-packet: https://nvd.nist.gov/vuln/detail/CVE-2021-23386. dns-packet is a dependency of multicast-dns. multicast-dns uses the fixed version of dns-packet as of version 7.2.3: https://github.com/mafintosh/multicast-dns/blob/309a1aa77fc85a81f04117ca16350b87a26faba1/package.json#L11, however bonjour currently only uses multicast-dns versions from the 6.x series: https://github.com/watson/bonjour/blob/master/package.json#L11; multicast-dns will need to be upgraded to pull in the fix for this CVE

@Trunk89
Copy link

Trunk89 commented Dec 16, 2021

Any chance this dependency will be bumped into a newer version anytime soon?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants