Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1343-1

Опубликовано: 11 окт. 2021
Источник: suse-cvrf

Описание

Security update for nodejs8

nodejs8 was updated to fix the following security issues:

  • CVE-2021-22930: http2: fixes use after free on close in stream canceling (bsc#1188917)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Список пакетов

openSUSE Leap 15.2
nodejs8-8.17.0-lp152.3.17.1
nodejs8-devel-8.17.0-lp152.3.17.1
nodejs8-docs-8.17.0-lp152.3.17.1
npm8-8.17.0-lp152.3.17.1

Описание

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.


Затронутые продукты
openSUSE Leap 15.2:nodejs8-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:nodejs8-devel-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:nodejs8-docs-8.17.0-lp152.3.17.1
openSUSE Leap 15.2:npm8-8.17.0-lp152.3.17.1

Ссылки