Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Debian 10 DLA-3776-1 Critical Node.js DoS And Info Disclosure Advisory

debian lts
Calendar Grey March 27, 2024
Scroller Debian Lts
Ubuntu Security Notice USN-8999-1 deals with security flaws in Python that may result in DoS and data leakage.
Vulnerabilities have been found in Node.js, which could lead to denial of service or information disclosure

Summary

CVE-2023-30590

Ben Smyth reported an inconsistency between implementation and
documented design of the The generateKeys() API function, which
only generates missing (or outdated) keys, that is, it only
generates a private key if none has been set yet.
The documented behavior has been updated to reflect the current
implementation.

CVE-2023-46809

It was discovered that Node.js was vulnerable to the Marvin Attack,
allowing a covert timing side-channel during PKCS#1 v1.5 padding
error handling. An attacker could remotely exploit the
vulnerability to decrypt captured RSA ciphertexts or forge
signatures, especially in scenarios involving API endpoints
processing Json Web Encryption messages.
The fix disables RSA_PKCS1_PADDING for crypto.privateDecrypt(), and
includes a security revert flag that can be used to restore support
(and the vulnerability).

CVE-2024-22025

It was discovered that Node.js was vulnerable to Denial of Service

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: nodejs
Version: 10.24.0~dfsg-1~deb10u4
CVE ID: CVE-2023-30590 CVE-2023-46809 CVE-2024-22025
Debian Bug: 1039990 1064055

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.