Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 40 FEDORA-2024-66b0bdad35 critical: yarnpkg denial of service

fedora
Calendar Grey October 24, 2024
Dist Fedora Esm H88
Keep informed about Fedora 40 yarnpkg security patches addressing vital concerns related to dependency oversight and service interruptions.
Update bundled ws (CVE-2024-37890) Update bundled elliptic to fix CVE-2024-48949.

Summary

Fast, reliable, and secure dependency management.

Update Information:

Update bundled ws (CVE-2024-37890) Update bundled elliptic to fix CVE-2024-48949.

Change Log

* Tue Oct 15 2024 Sandro Mani - 1.22.22-5 - Update bundled ws (CVE-2024-37890) * Thu Oct 10 2024 Sandro Mani - 1.22.22-4 - Update bundled elliptic (CVE-2024-48949) * Sat Jul 20 2024 Fedora Release Engineering - 1.22.22-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2303429 - CVE-2024-37890 yarnpkg: denial of service when handling a request with many HTTP headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303429 [ 2 ] Bug #2317790 - CVE-2024-48949 yarnpkg: Missing Validation in Elliptic's EDDSA Signature Verification [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2317790

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-66b0bdad35' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: yarnpkg
Product: Fedora 40
Version: 1.22.22
Release: 5.fc40
Summary: Fast, reliable, and secure dependency management.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here