Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0455-1

Опубликовано: 25 фев. 2020
Источник: suse-cvrf

Описание

Security update for nodejs10

This update for nodejs10 fixes the following issues:

nodejs10 was updated to version 10.19.0.

Security issues fixed:

  • CVE-2019-15604: Fixed a remotely triggerable assertion in the TLS server via a crafted certificate string (CVE-2019-15604, bsc#1163104).
  • CVE-2019-15605: Fixed an HTTP request smuggling vulnerability via malformed Transfer-Encoding header (CVE-2019-15605, bsc#1163102).
  • CVE-2019-15606: Fixed the white space sanitation of HTTP headers (CVE-2019-15606, bsc#1163103).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1
SUSE Linux Enterprise Module for Web and Scripting 15
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP1
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1
SUSE Linux Enterprise Server 15-LTSS
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1
SUSE Linux Enterprise Server for SAP Applications 15
nodejs10-10.19.0-1.18.1
nodejs10-devel-10.19.0-1.18.1
nodejs10-docs-10.19.0-1.18.1
npm10-10.19.0-1.18.1

Описание

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-devel-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-docs-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:npm10-10.19.0-1.18.1

Ссылки

Описание

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-devel-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-docs-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:npm10-10.19.0-1.18.1

Ссылки

Описание

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-devel-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:nodejs10-docs-10.19.0-1.18.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:npm10-10.19.0-1.18.1

Ссылки