Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0356-1

Опубликовано: 27 фев. 2021
Источник: suse-cvrf

Описание

Security update for nodejs14

This update for nodejs14 fixes the following issues:

  • New upstream LTS version 14.16.0:
    • CVE-2021-22883: HTTP2 'unknownProtocol' cause Denial of Service by resource exhaustion (bsc#1182619)
    • CVE-2021-22884: DNS rebinding in --inspect (bsc#1182620)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Список пакетов

openSUSE Leap 15.2
nodejs14-14.16.0-lp152.8.1
nodejs14-devel-14.16.0-lp152.8.1
nodejs14-docs-14.16.0-lp152.8.1
npm14-14.16.0-lp152.8.1

Описание

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.


Затронутые продукты
openSUSE Leap 15.2:nodejs14-14.16.0-lp152.8.1
openSUSE Leap 15.2:nodejs14-devel-14.16.0-lp152.8.1
openSUSE Leap 15.2:nodejs14-docs-14.16.0-lp152.8.1
openSUSE Leap 15.2:npm14-14.16.0-lp152.8.1

Ссылки

Описание

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain. As long as the attacker uses the "localhost6" domain, they can still apply the attack described in CVE-2018-7160.


Затронутые продукты
openSUSE Leap 15.2:nodejs14-14.16.0-lp152.8.1
openSUSE Leap 15.2:nodejs14-devel-14.16.0-lp152.8.1
openSUSE Leap 15.2:nodejs14-docs-14.16.0-lp152.8.1
openSUSE Leap 15.2:npm14-14.16.0-lp152.8.1

Ссылки