MGASA-2022-0422 - Updated nodejs packages fix security vulnerability

Publication date: 13 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0422.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-43548

DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548)
In addition, 14.21.0 has provided the following changes:
deps
  update corepack to 0.14.2 (Node.js GitHub Bot) #44775
src
  add --openssl-shared-config option (Daniel Bevenius) #43124

References:
- https://bugs.mageia.org/show_bug.cgi?id=31078
- https://github.com/nodejs/node/releases/tag/v14.21.1
- https://github.com/nodejs/node/releases/tag/v14.21.0
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/
- https://nodejs.org/en/blog/release/v18.12.1/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43548

SRPMS:
- 8/core/nodejs-14.21.1-1.1.mga8

Mageia 2022-0422: nodejs security update

DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548) In addition, 14.21.0 has provided the following changes: deps update corepack to 0.14.2 (Node.js GitHub B...

Summary

DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548) In addition, 14.21.0 has provided the following changes: deps update corepack to 0.14.2 (Node.js GitHub Bot) #44775 src add --openssl-shared-config option (Daniel Bevenius) #43124

References

- https://bugs.mageia.org/show_bug.cgi?id=31078

- https://github.com/nodejs/node/releases/tag/v14.21.1

- https://github.com/nodejs/node/releases/tag/v14.21.0

- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/

- https://nodejs.org/en/blog/release/v18.12.1/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43548

Resolution

MGASA-2022-0422 - Updated nodejs packages fix security vulnerability

SRPMS

- 8/core/nodejs-14.21.1-1.1.mga8

Severity
Publication date: 13 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0422.html
Type: security
CVE: CVE-2022-43548

Related News