Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 7 MGASA-2021-0068 Moderate: Nodejs-Ini Malicious Input Exploit

mageia
Calendar Grey February 5, 2021
Dist Mageia Esm H88
MGASA-2021-0069 addresses a vulnerability in the package libxml2, which could be exploited via crafted XML input, impacting users of Mageia 8.
It was discovered that there was an issue in nodejs-ini, where an application could be exploited by a malicious input file

Summary

It was discovered that there was an issue in nodejs-ini, where an application could be exploited by a malicious input file. This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context (CVE-2020-7788).

References

- https://bugs.mageia.org/show_bug.cgi?id=27901

- https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html

- https://www.cve.org/CVERecord?id=CVE-2020-7788

Resolution

SRPMS

- 7/core/nodejs-ini-1.3.8-1.mga7

Publication date: 05 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0068.html
Type: security
CVE: CVE-2020-7788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here