Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2021-0360 Moderate: Node.js Libuv Out-Of-Bounds Access

mageia
Calendar Grey July 20, 2021
Dist Mageia Esm H88
Revised libuv modules address buffer overflow vulnerability impacting Node.js, released on Jul 20, 2021.
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII

Summary

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo(). (CVE-2021-22918).

References

- https://bugs.mageia.org/show_bug.cgi?id=29231

- https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/

- https://lists.debian.org/debian-security-announce/2021/msg00119.html

- https://ubuntu.com/security/notices/USN-5007-1

- https://www.cve.org/CVERecord?id=CVE-2021-22918

Resolution

SRPMS

- 8/core/libuv-1.40.0-1.1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 20 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0360.html
Type: security
CVE: CVE-2021-22918

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here