Описание
Security update for nodejs8
nodejs8 was updated to fix the following security issues:
- CVE-2021-22930: http2: fixes use after free on close in stream canceling (bsc#1188917)
Список пакетов
openSUSE Leap 15.3
nodejs8-8.17.0-10.15.11
nodejs8-devel-8.17.0-10.15.11
nodejs8-docs-8.17.0-10.15.11
npm8-8.17.0-10.15.11
Ссылки
- E-Mail link for openSUSE-SU-2021:3294-1
- SUSE Security Ratings
- SUSE Bug 1188917
- SUSE CVE CVE-2021-22930 page
Описание
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Затронутые продукты
openSUSE Leap 15.3:nodejs8-8.17.0-10.15.11
openSUSE Leap 15.3:nodejs8-devel-8.17.0-10.15.11
openSUSE Leap 15.3:nodejs8-docs-8.17.0-10.15.11
openSUSE Leap 15.3:npm8-8.17.0-10.15.11
Ссылки
- CVE-2021-22930
- SUSE Bug 1188917
- SUSE Bug 1189368