Описание
Security update for rhino
This update for rhino fixes the following issues:
Update to version 1.7.15.1.
Security issues fixed:
- CVE-2025-66453: high CPU consumption when processing specific numbers via the
toFixed()function (bsc#1254481).
Other changes and issues fixed:
- Version 1.7.15:
- Basic support for 'rest parameters'.
- Improvements in Unicode support.
- 'Symbol.species' implemented in many places.
- More correct property ordering in many places.
- Miscellaneous improvements and bug fixes.
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP6
rhino-1.7.15.1-150200.12.7.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6
rhino-1.7.15.1-150200.12.7.1
rhino-demo-1.7.15.1-150200.12.7.1
rhino-engine-1.7.15.1-150200.12.7.1
rhino-javadoc-1.7.15.1-150200.12.7.1
rhino-runtime-1.7.15.1-150200.12.7.1
Ссылки
- Link for SUSE-SU-2025:4390-1
- E-Mail link for SUSE-SU-2025:4390-1
- SUSE Security Ratings
- SUSE Bug 1254481
- SUSE CVE CVE-2025-66453 page
Описание
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:rhino-1.7.15.1-150200.12.7.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6:rhino-1.7.15.1-150200.12.7.1
openSUSE Leap 15.6:rhino-demo-1.7.15.1-150200.12.7.1
Ссылки
- CVE-2025-66453
- SUSE Bug 1254481