Описание
Security update for nodejs14
This update for nodejs14 fixes the following issues:
New upstream LTS version 14.16.0:
- CVE-2021-22883: HTTP2 'unknownProtocol' cause Denial of Service by resource exhaustion (bsc#1182619)
- CVE-2021-22884: DNS rebinding in --inspect (bsc#1182620)
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 12
Ссылки
- Link for SUSE-SU-2021:0650-1
- E-Mail link for SUSE-SU-2021:0650-1
- SUSE Security Ratings
- SUSE Bug 1182619
- SUSE Bug 1182620
- SUSE CVE CVE-2021-22883 page
- SUSE CVE CVE-2021-22884 page
Описание
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Затронутые продукты
Ссылки
- CVE-2021-22883
- SUSE Bug 1182619
Описание
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain. As long as the attacker uses the "localhost6" domain, they can still apply the attack described in CVE-2018-7160.
Затронутые продукты
Ссылки
- CVE-2021-22884
- SUSE Bug 1182620
- SUSE Bug 1188549
- SUSE Bug 1201328