USN-6380-1: Node.js vulnerabilities

Read Time:1 Minute, 20 Second

Rogier Schouten discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-15604)

Ethan Rubinson discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15605)

Alyssa Wilk discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15606)

Tobias Niessen discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-8174)

It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2020-8265, CVE-2020-8287)

Read More

golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc40 golang-github-envoyproxy-control-plane-0.11.1-1.fc40 golang-github-nats-io-1.29.0-5.fc40 golang-google-protobuf-1.31.0-1.fc40 nats-server-2.9.22-1.fc40

Read Time:18 Second

FEDORA-2023-a1b28cf117

Packages in this update:

golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc40
golang-github-envoyproxy-control-plane-0.11.1-1.fc40
golang-github-nats-io-1.29.0-5.fc40
golang-google-protobuf-1.31.0-1.fc40
nats-server-2.9.22-1.fc40

Update description:

Security fix for CVE-2022-41717

Read More