This update for nodejs14 fixes the following issues:
- CVE-2021-23343: Fixed ReDoS via splitDeviceRe, splitTailRe and
splitPathRe (bsc#1192153).
- CVE-2021-32803: Fixed insufficient symlink protection in node-tar
allowing arbitrary file creation and overwrite (bsc#1191963).
- CVE-2021-32804: Fixed insufficient absolute path sanitization in
node-tar allowing arbitrary file creation and overwrite (bsc#1191962).
- CVE-2021-3918: Fixed improper controlled modification of object
prototype attributes in json-schema (bsc#1192696).
- CVE-2021-3807: Fixed regular expression denial of service (ReDoS)
matching ANSI escape codes in node-ansi-regex (bsc#1192154).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2022-715=1
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2022-715=1
- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):
nodejs14-14.19.0-15.27.1
nodejs14-debuginfo-14.19.0-15.27.1
nodejs14-debugsource-14.19.0-15.27.1
nodejs14-devel-14.19.0-15.27.1
npm14-14.19.0-15.27.1
- openSUSE Leap 15.4 (noarch):
nodejs14-docs-14.19.0-15.27.1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
nodejs14-14.19.0-15.27.1
nodejs14-debuginfo-14.19.0-15.27.1
nodejs14-debugsource-14.19.0-15.27.1
nodejs14-devel-14.19.0-15.27.1
npm14-14.19.0-15.27.1
- openSUSE Leap 15.3 (noarch):
nodejs14-docs-14.19.0-15.27.1
https://www.suse.com/security/cve/CVE-2021-23343.html
https://www.suse.com/security/cve/CVE-2021-32803.html
https://www.suse.com/security/cve/CVE-2021-32804.html
https://www.suse.com/security/cve/CVE-2021-3807.html
https://www.suse.com/security/cve/CVE-2021-3918.html
https://bugzilla.suse.com/1191962
https://bugzilla.suse.com/1191963
https://bugzilla.suse.com/1192153
https://bugzilla.suse.com/1192154
https://bugzilla.suse.com/1192696
Get the latest Linux and open source security news straight to your inbox.