Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4259-1

Опубликовано: 30 окт. 2023
Источник: suse-cvrf

Описание

Security update for nodejs12

This update for nodejs12 fixes the following issues:

  • CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190)
  • CVE-2023-38552: Fixed an integrity checks according to policies that could be circumvented. (bsc#1216272)

Список пакетов

SUSE Linux Enterprise Module for Web and Scripting 12
nodejs14-14.21.3-6.49.1
nodejs14-devel-14.21.3-6.49.1
nodejs14-docs-14.21.3-6.49.1
npm14-14.21.3-6.49.1

Описание

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-devel-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-docs-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm14-14.21.3-6.49.1

Ссылки

Описание

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-devel-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs14-docs-14.21.3-6.49.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm14-14.21.3-6.49.1

Ссылки