Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 30: FEDORA-2019-5a6a7bc12c Critical: Node.js Denial of Service

fedora
Calendar Grey August 24, 2019
Dist Fedora Esm H88
The update to Node.js 12.0.0 addresses critical security issues for Ubuntu 20.04 users.
Update to Node.js 10.6.13

Summary

Node.js is a platform built on Chrome's JavaScript runtime

for easily building fast, scalable network applications.

Node.js uses an event-driven, non-blocking I/O model that

makes it lightweight and efficient, perfect for data-intensive

real-time applications that run across distributed devices.

Update to Node.js 10.6.13

* Fri Aug 16 2019 Stephen Gallagher - 1:10.16.3-1

- Update to 10.16.3 security release

- Resolves: CVE-2019-9511 "Data Dribble"

- Resolves: CVE-2019-9512 "Ping Flood"

- Resolves: CVE-2019-9513 "Resource Loop"

- Resolves: CVE-2019-9514 "Reset Flood"

- Resolves: CVE-2019-9515 "Settings Flood"

- Resolves: CVE-2019-9516 "0-Length Headers Leak"

- Resolves: CVE-2019-9517 "Internal Data Buffering"

- Resolves: CVE-2019-9518 "Empty Frames Flood"

-

* Mon Jun 3 2019 Stephen Gallagher - 1:10.16.0-3

- Change v8-devel release stream to avoid duplicate NEVRAs

* Fri May 31 2019 Stephen Gallagher - 1:10.16.0-1

- Update to 10.16.0

- https://nodejs.org/en/blog/release/v10.16.0/

* Wed Apr 24 2019 Stephen Gallagher - 1:10.15.3-2

- Fix upgrade bug for v8-devel (BZ #1702609)

[ 1 ] Bug #1741979 - CVE-2019-9516 nodejs: HTTP/2: 0-length headers leads to denial of service [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741979

[ 2 ] Bug #1741974 - CVE-2019-9517 nodejs: HTTP/2: request for large response leads to denial of service [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741974

[ 3 ] Bug #1741969 - CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resources consumption [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741969

[ 4 ] Bug #1741968 - CVE-2019-9515 nodejs: http/2: HTTP/2 flood using SETTINGS frames results in unbounded memory growth [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741968

[ 5 ] Bug #1741967 - CVE-2019-9513 nodejs: HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741967

[ 6 ] Bug #1741964 - CVE-2019-9514 nodejs: http/2: HTTP/2 flood using HEADERS frames results in unbounded memory growth [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741964

[ 7 ] Bug #1741962 - CVE-2019-9512 nodejs: http/2: HTTP/2 flood using PING frames results in unbounded memory growth [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1741962

su -c 'dnf upgrade --advisory FEDORA-2019-5a6a7bc12c' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 10.16.3
Release: 1.fc30
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here