Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4390-1

Опубликовано: 12 дек. 2025
Источник: suse-cvrf

Описание

Security update for rhino

This update for rhino fixes the following issues:

Update to version 1.7.15.1.

Security issues fixed:

  • CVE-2025-66453: high CPU consumption when processing specific numbers via the toFixed() function (bsc#1254481).

Other changes and issues fixed:

  • Version 1.7.15:
    • Basic support for 'rest parameters'.
    • Improvements in Unicode support.
    • 'Symbol.species' implemented in many places.
    • More correct property ordering in many places.
    • Miscellaneous improvements and bug fixes.

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP6
rhino-1.7.15.1-150200.12.7.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6
rhino-1.7.15.1-150200.12.7.1
rhino-demo-1.7.15.1-150200.12.7.1
rhino-engine-1.7.15.1-150200.12.7.1
rhino-javadoc-1.7.15.1-150200.12.7.1
rhino-runtime-1.7.15.1-150200.12.7.1

Описание

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:rhino-1.7.15.1-150200.12.7.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6:rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6:rhino-demo-1.7.15.1-150200.12.7.1

Ссылки