Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2022-0455 Critical Nodejs Symlink Vulnerability Fix Available

mageia
Calendar Grey April 2, 2021
Dist Mageia Esm H88
The latest version of the nodejs-chownr library addresses a serious vulnerability that permitted unauthorized access to directories through symbolic link manipulation.
Updated nodejs-chownr package fixes security vulnerability: A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into desce...

Summary

Updated nodejs-chownr package fixes security vulnerability:
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks (CVE-2017-18869).

References

- https://bugs.mageia.org/show_bug.cgi?id=27971

- https://www.cve.org/CVERecord?id=CVE-2017-18869

Resolution

SRPMS

- 7/core/nodejs-chownr-1.1.0-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0169.html
Type: security
CVE: CVE-2017-18869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here