Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2021-0092 Critical Update Resolves Node.js Denial of Service Threat

mageia
Calendar Grey February 28, 2021
Dist Mageia Esm H88
Uncover the latest security patches implemented in Mageia that address vulnerabilities in Node.js, specifically focusing on Denial of Service (DoS) attacks and DNS rebinding threats.
Two vulnerabilities were discovered in Node.js, which could result in denial of service or DNS rebinding attacks

Summary

Two vulnerabilities were discovered in Node.js, which could result in denial of service or DNS rebinding attacks. Upgrade from Mageia 7 to 8 problem fixed.

References

- https://bugs.mageia.org/show_bug.cgi?id=28445

- https://bugs.mageia.org/show_bug.cgi?id=28481

- https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/

- https://nodejs.org/en/blog/release/v10.24.0/

- https://nodejs.org/en/blog/release/v14.16.0/

- https://www.cve.org/CVERecord?id=CVE-2021-22883

- https://www.cve.org/CVERecord?id=CVE-2021-22884

Resolution

SRPMS

- 7/core/nodejs-10.24.0-10.mga7

- 8/core/nodejs-14.16.0-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0092.html
Type: security
CVE: CVE-2021-22883, CVE-2021-22884

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here