Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 8: 2022-0422 Critical: Nodejs DNS Rebinding Issue

mageia
Calendar Grey November 12, 2022
Dist Mageia Esm H88
The Mageia team has resolved a serious DNS rebinding vulnerability associated with CVE-2022-43548, enhancing the security of nodejs packages in their latest update from November 2022.
DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548) In addition, 14.21.0 has provided the following changes: deps update corepack to 0.14.2 (Node.js GitHub B...

Summary

DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548) In addition, 14.21.0 has provided the following changes: deps update corepack to 0.14.2 (Node.js GitHub Bot) #44775 src add --openssl-shared-config option (Daniel Bevenius) #43124

References

- https://bugs.mageia.org/show_bug.cgi?id=31078

- https://github.com/nodejs/node/releases/tag/v14.21.1

- https://github.com/nodejs/node/releases/tag/v14.21.0

- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/

- https://nodejs.org/en/blog/release/v18.12.1/

- https://www.cve.org/CVERecord?id=CVE-2022-43548

Resolution

SRPMS

- 8/core/nodejs-14.21.1-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0422.html
Type: security
CVE: CVE-2022-43548

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here