Описание
Security update for nodejs8
nodejs8 was updated to fix the following security issues:
- CVE-2021-22930: http2: fixes use after free on close in stream canceling (bsc#1188917)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Список пакетов
openSUSE Leap 15.2
nodejs8-8.17.0-lp152.3.17.1
nodejs8-devel-8.17.0-lp152.3.17.1
nodejs8-docs-8.17.0-lp152.3.17.1
npm8-8.17.0-lp152.3.17.1
Ссылки
- E-Mail link for openSUSE-SU-2021:1343-1
- SUSE Security Ratings
- SUSE Bug 1188917
- SUSE CVE CVE-2021-22930 page
Описание
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Затронутые продукты
openSUSE Leap 15.2:nodejs8-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:nodejs8-devel-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:nodejs8-docs-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:npm8-8.17.0-lp152.3.17.1
Ссылки
- CVE-2021-22930
- SUSE Bug 1188917
- SUSE Bug 1189368