Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:4034

Опубликовано: 31 авг. 2023
Источник: rocky
Оценка: Important

Описание

Important: nodejs:16 security update

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

  • c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067)

  • c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130)

  • c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147)

  • c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
nodejsx86_642.module+el8.8.0+1338+00a07a77nodejs-16.19.1-2.module+el8.8.0+1338+00a07a77.x86_64.rpm
nodejs-develx86_642.module+el8.8.0+1338+00a07a77nodejs-devel-16.19.1-2.module+el8.8.0+1338+00a07a77.x86_64.rpm
nodejs-docsnoarch2.module+el8.8.0+1338+00a07a77nodejs-docs-16.19.1-2.module+el8.8.0+1338+00a07a77.noarch.rpm
nodejs-docsnoarch2.module+el8.8.0+1338+00a07a77nodejs-docs-16.19.1-2.module+el8.8.0+1338+00a07a77.noarch.rpm
nodejs-full-i18nx86_642.module+el8.8.0+1338+00a07a77nodejs-full-i18n-16.19.1-2.module+el8.8.0+1338+00a07a77.x86_64.rpm
nodejs-nodemonnoarch3.module+el8.7.0+1178+d52dba78nodejs-nodemon-2.0.20-3.module+el8.7.0+1178+d52dba78.noarch.rpm
nodejs-nodemonnoarch3.module+el8.7.0+1178+d52dba78nodejs-nodemon-2.0.20-3.module+el8.7.0+1178+d52dba78.noarch.rpm
nodejs-packagingnoarch1.module+el8.7.0+1108+49363b0dnodejs-packaging-25-1.module+el8.7.0+1108+49363b0d.noarch.rpm
nodejs-packagingnoarch1.module+el8.7.0+1108+49363b0dnodejs-packaging-25-1.module+el8.7.0+1108+49363b0d.noarch.rpm
npmx86_641.16.19.1.2.module+el8.8.0+1338+00a07a77npm-8.19.3-1.16.19.1.2.module+el8.8.0+1338+00a07a77.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
больше 2 лет назад

Security update for libcares2

suse-cvrf
больше 2 лет назад

Security update for c-ares

rocky
больше 2 лет назад

Important: nodejs:18 security update

oracle-oval
больше 2 лет назад

ELSA-2023-4034: nodejs:16 security update (IMPORTANT)

oracle-oval
больше 2 лет назад

ELSA-2023-3586: nodejs security update (IMPORTANT)