Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1317

Опубликовано: 15 апр. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-1317: nodejs:10 security update (IMPORTANT)

nodejs [1:10.19.0-2]

  • Resolves: RHBZ#1811498

[1:10.19.0-1]

  • Rebase to 10.19.0 to fix CVE-2019-15604 to CVE-2019-15606

[1:10.16.3-1]

  • Rebase to 10.16.3 to fix CVE-2019-9511 to CVE-2019-9518

[1:10.14.1-1]

  • Resolves: RHBZ#1644207
  • fixes node-gyp permissions
  • rebase

[1:10.11.0-2]

  • BuildRequire nodejs-packaging for proper npm dependency generation
  • Resolves: rhbz#1615947

[1:10.11.0-1]

  • Rebase to 10.11.0
  • Import changes from fedora
  • Resolves: rhbz#1621766

[1:10.7.0-5]

  • Import sources from fedora
  • Allow using python2 at %build and %install
  • turn off debug for aarch64

[1:10.7.0-4]

  • Fix npm upgrade scriptlet
  • Fix unexpected trailing .1 in npm release field

[1:10.7.0-3]

  • Restore annotations to binaries
  • Fix unexpected trailing .1 in release field

[1:10.7.0-2]

[1:10.5.0-1.1]

[1:10.5.0-1]

[1:10.4.1-1]

[1:10.4.0-1]

[1:10.3.0-1]

[1:10.2.1-2]

  • Fix up bare 'python' to be python2
  • Drop redundant entry in docs section

[1:10.2.1-1]

[1:10.2.0-1]

[1:10.1.0-3]

  • Fix incorrect rpm macro

[1:10.1.0-2]

  • Include upstream v8 fix for ppc64[le]
  • Disable debug build on ppc64[le] and s390x

[1:10.1.0-1]

[1:10.0.0-1]

[1:9.11.1-2]

  • Use standard Fedora linker flags (bug #1543859)

[1:9.11.1-1]

[1:9.10.0-1]

[1:9.9.0-1]

[1:9.8.0-1]

[1:9.7.0-1]

[1:9.6.1-1]

[1:9.5.0-1]

  • Package Node.js 9.5.0

[1:8.9.4-2]

  • Fix incorrect Requires:

[1:8.9.4-1]

[1:8.9.3-2]

[1:8.9.1-2]

  • Rebuild for ICU 60.1

[1:8.9.1-1]

  • Update to 8.9.1

[1:8.9.0-1]

  • Update to 8.9.0
  • Drop upstreamed patch

[1:8.8.1-1]

  • Update to 8.8.1 to fix a regression

[1:8.8.0-1]

[1:8.7.0-1]

[1:8.6.0-2]

  • Use bcond macro instead of bootstrap conditional

[1:8.6.0-1]

[1:8.5.0-3]

  • Build with bootstrap + bundle libuv for modularity
  • backport patch for aarch64 debug build

[1:8.5.0-2]

[1:8.5.0-1]

[1:8.4.0-2]

  • Refactor openssl BR

[1:8.4.0-1]

[1:8.3.0-1]

[1:8.2.1-2]

  • Bump release to fix broken dependencies

[1:8.2.1-1.2]

[1:8.2.1-1.1]

[1:8.2.1-1]

[1:8.2.0-1]

[1:8.1.4-3]

  • s/BuildRequires/Requires/ for http-parser-devel%{?_isa}

[1:8.1.4-2]

  • Rename python-devel to python2-devel
  • own %{_pkgdocdir}/npm

[1:8.1.4-1]

[1:8.1.3-1]

[1:8.1.2-1]

  • Update to v8.1.2
  • remove GCC 7 patch, as it is now fixed in node >= 6.12

nodejs-nodemon nodejs-packaging

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module nodejs:10 is enabled

nodejs

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-devel

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-docs

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-nodemon

1.18.3-1.module+el8.1.0+5392+4d6b561f

nodejs-packaging

17-3.module+el8.1.0+5392+4d6b561f

npm

6.13.4-1.10.19.0.2.module+el8.1.0+5572+a2a7be63

Oracle Linux x86_64

Module nodejs:10 is enabled

nodejs

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-devel

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-docs

10.19.0-2.module+el8.1.0+5572+a2a7be63

nodejs-nodemon

1.18.3-1.module+el8.1.0+5392+4d6b561f

nodejs-packaging

17-3.module+el8.1.0+5392+4d6b561f

npm

6.13.4-1.10.19.0.2.module+el8.1.0+5572+a2a7be63

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
redhat
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
debian
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) ...

suse-cvrf
около 5 лет назад

Security update for icu

Уязвимость ELSA-2020-1317