Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Fedora 33: FEDORA-2021-fb1a136393 Moderate: Node.js HTTP Fix

fedora
Calendar Grey January 9, 2021
Dist Fedora Esm H88
Node.js version 14.15.4 brings crucial patches for various security vulnerabilities, tackling threats like HTTP request smuggling and addressing use-after-free concerns.
Update to Node.js 14.15.4 security release

Summary

Node.js is a platform built on Chrome's JavaScript runtime

for easily building fast, scalable network applications.

Node.js uses an event-driven, non-blocking I/O model that

makes it lightweight and efficient, perfect for data-intensive

real-time applications that run across distributed devices.

Update to Node.js 14.15.4 security release

* Mon Jan 4 2021 Stephen Gallagher - 1:14.15.4-1

- Update to 14.15.4

[ 1 ] Bug #1912857 - CVE-2020-8265 nodejs: use-after-free in its TLS implementation [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1912857

[ 2 ] Bug #1912860 - CVE-2020-8265 nodejs:14/nodejs: use-after-free in its TLS implementation [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1912860

[ 3 ] Bug #1912865 - CVE-2020-8287 nodejs: HTTP Request Smuggling via two copies of a header field in a http request [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1912865

[ 4 ] Bug #1912867 - CVE-2020-8287 nodejs:14/nodejs: HTTP Request Smuggling via two copies of a header field in a http request [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1912867

su -c 'dnf upgrade --advisory FEDORA-2021-fb1a136393' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 33
Version: 14.15.4
Release: 1.fc33
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here