MGASA-2024-0110 - Updated nodejs packages fix security vulnerabilities

Publication date: 05 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0110.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-27982,
     CVE-2024-27983

Nodejs 20.12.1 release fixes 2 CVE:
* CVE-2024-27983 - Assertion failed in
node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash-
(High)
* CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation
- (Medium)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33055
- https://github.com/nodejs/node/releases/tag/v20.12.1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27982
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27983

SRPMS:
- 9/core/nodejs-20.12.1-1.mga9

Mageia 2024-0110: nodejs security update

Nodejs 20.12.1 release fixes 2 CVE: * CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High) * CVE-2024-27982 - HTTP R...

Summary

References

- https://bugs.mageia.org/show_bug.cgi?id=33055

- https://github.com/nodejs/node/releases/tag/v20.12.1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27982

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27983

Resolution

MGASA-2024-0110 - Updated nodejs packages fix security vulnerabilities

SRPMS

- 9/core/nodejs-20.12.1-1.mga9

Severity
Publication date: 05 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0110.html
Type: security
CVE: CVE-2024-27982, CVE-2024-27983

Related News