Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

openSUSE: 2021:2327-1 Important Security Issues In Nodejs12

opensuse
Calendar Grey July 14, 2021
Scroller Opensuse
A new patch for openSUSE fixes 7 bugs in nodejs14, tackling significant security flaws. Continue reading for more information.
An update that fixes 6 vulnerabilities is now available

Description

This update for nodejs12 fixes the following issues:

- update to 12.22.2:

- CVE-2021-22918: Out of bounds read (bsc#1187973)

- CVE-2021-23362: ssri Regular Expression Denial of Service and

hosted-git-info (bsc#1187977)

- CVE-2021-27290: Regular Expression Denial of Service (bsc#1187976)

- CVE-2021-3450: OpenSSL - CA certificate check bypass with

X509_V_FLAG_X509_STRICT (bsc#1183851)

- CVE-2021-3449: OpenSSL - NULL pointer deref in signature_algorithms

processing (bsc#1183852)

- CVE-2020-7774: npm - Update y18n to fix Prototype-Pollution (bsc#1184450)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2327=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

nodejs12-12.22.2-4.16.1

nodejs12-debuginfo-12.22.2-4.16.1

nodejs12-debugsource-12.22.2-4.16.1

nodejs12-devel-12.22.2-4.16.1

npm12-12.22.2-4.16.1

- openSUSE Leap 15.3 (noarch):

nodejs12-docs-12.22.2-4.16.1

References

https://www.suse.com/security/cve/CVE-2020-7774.html

https://www.suse.com/security/cve/CVE-2021-22918.html

https://www.suse.com/security/cve/CVE-2021-23362.html

https://www.suse.com/security/cve/CVE-2021-27290.html

https://www.suse.com/security/cve/CVE-2021-3449.html

https://www.suse.com/security/cve/CVE-2021-3450.html

https://bugzilla.suse.com/1183851

https://bugzilla.suse.com/1183852

https://bugzilla.suse.com/1184450

https://bugzilla.suse.com/1187973

https://bugzilla.suse.com/1187976

https://bugzilla.suse.com/1187977

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:2327-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.