Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Mageia 8 MGASA-2022-0354 Moderate: Nodejs DNS Rebinding and HTTP Issues

mageia
Calendar Grey October 1, 2022
Dist Mageia Esm H88
Recent updates to Node.js packages tackle critical security vulnerabilities in Mageia linked to DNS rebinding and HTTP parsing issues. Refer to the advisory for details.
DNS rebinding in --inspect on macOS (CVE-2022-32212) Bypass via obs-fold mechanic (CVE-2022-32213) HTTP Request Smuggling Due to Incorrect Parsing of Header Fields (CVE-2022-35256)...

Summary

DNS rebinding in --inspect on macOS (CVE-2022-32212) Bypass via obs-fold mechanic (CVE-2022-32213) HTTP Request Smuggling Due to Incorrect Parsing of Header Fields (CVE-2022-35256)

References

- https://bugs.mageia.org/show_bug.cgi?id=30887

- https://github.com/nodejs/node/releases/tag/v14.20.1

- https://nodejs.org/en/blog/vulnerability/september-2022-security-releases/

- https://www.cve.org/CVERecord?id=CVE-2022-32212

- https://www.cve.org/CVERecord?id=CVE-2022-32213

- https://www.cve.org/CVERecord?id=CVE-2022-35256

Resolution

SRPMS

- 8/core/nodejs-14.20.1-2.1.mga8

Publication date: 01 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0354.html
Type: security
CVE: CVE-2022-32212, CVE-2022-32213, CVE-2022-35256

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here