Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4374-1

Опубликовано: 06 нояб. 2023
Источник: suse-cvrf

Описание

Security update for nodejs12

This update for nodejs12 fixes the following issues:

  • CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190)
  • CVE-2023-38552: Fixed an integrity checks according to policies that could be circumvented. (bsc#1216272)

Список пакетов

SUSE Enterprise Storage 7.1
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise Server 15 SP2-LTSS
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise Server 15 SP3-LTSS
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
SUSE Manager Server 4.2
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2
openSUSE Leap 15.4
nodejs12-12.22.12-150200.4.53.2
nodejs12-devel-12.22.12-150200.4.53.2
nodejs12-docs-12.22.12-150200.4.53.2
npm12-12.22.12-150200.4.53.2

Описание

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.


Затронутые продукты
SUSE Enterprise Storage 7.1:nodejs12-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:nodejs12-devel-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:nodejs12-docs-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:npm12-12.22.12-150200.4.53.2

Ссылки

Описание

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.


Затронутые продукты
SUSE Enterprise Storage 7.1:nodejs12-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:nodejs12-devel-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:nodejs12-docs-12.22.12-150200.4.53.2
SUSE Enterprise Storage 7.1:npm12-12.22.12-150200.4.53.2

Ссылки