Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Fedora 39: yarnpkg 2024-d79685d847 Security Advisory Updates

fedora
Calendar Grey October 24, 2024
Dist Fedora Esm H88
Fedora's yarnpkg security advisory updates address CVE-2024-37890 and CVE-2024-48949 with essential fixes.
Update bundled ws (CVE-2024-37890) Update bundled dependencies to fix CVE-2024-48949.

Summary

Fast, reliable, and secure dependency management.

Update Information:

Update bundled ws (CVE-2024-37890) Update bundled dependencies to fix CVE-2024-48949.

Change Log

* Tue Oct 15 2024 Sandro Mani - 1.22.22-5 - Update bundled ws (CVE-2024-37890) * Thu Oct 10 2024 Sandro Mani - 1.22.22-4 - Update bundled elliptic (CVE-2024-48949) * Sat Jul 20 2024 Fedora Release Engineering - 1.22.22-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Thu Jul 4 2024 Sandro Mani - 1.22.22-2 - Backport patch for CVE-2024-4067 * Sat Mar 9 2024 Sandro Mani - 1.22.22-1 - Update to 1.22.22

References


[ 1 ] Bug #2303429 - CVE-2024-37890 yarnpkg: denial of service when handling a request with many HTTP headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303429 [ 2 ] Bug #2317789 - CVE-2024-48949 yarnpkg: Missing Validation in Elliptic's EDDSA Signature Verification [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2317789

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d79685d847' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: yarnpkg
Product: Fedora 39
Version: 1.22.22
Release: 5.fc39
Summary: Fast, reliable, and secure dependency management.

Topics%20covered

Topics Covered

No topics assigned

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here