Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Fedora: FSA-2021-1324 Important: rh-python36-python Security Patch

red hat
Calendar Grey June 18, 2020
Scroller Redhat
Red Hat Security Notification: Moderate rh-nodejs8-nodejs security patch released to address multiple vulnerabilities.
An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
The following packages have been upgraded to a later upstream version: rh-nodejs8-nodejs (8.17.0). (BZ#1829414)
Security Fix(es):
* nodejs-brace-expansion: Regular expression denial of service (CVE-2017-18077)
* nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js (CVE-2017-18869)
* nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js (CVE-2018-3737)
* nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties (CVE-2018-3750)
* npm: Symlink reference outside of node_modules folder through the bin field upon installation (CVE-2019-16775)
* npm: Arbitrary file write via constructed entry in the package.json bin field (CVE-2019-16776)
* npm: Global node_modules Binary Overwrite (CVE-2019-16777)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2017-18077 https://access.redhat.com/security/cve/CVE-2017-18869 https://access.redhat.com/security/cve/CVE-2018-3737 https://access.redhat.com/security/cve/CVE-2018-3750 https://access.redhat.com/security/cve/CVE-2019-16775 https://access.redhat.com/security/cve/CVE-2019-16776 https://access.redhat.com/security/cve/CVE-2019-16777 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-nodejs8-nodejs-8.17.0-2.el7.src.rpm
aarch64: rh-nodejs8-nodejs-8.17.0-2.el7.aarch64.rpm rh-nodejs8-nodejs-debuginfo-8.17.0-2.el7.aarch64.rpm rh-nodejs8-nodejs-devel-8.17.0-2.el7.aarch64.rpm rh-nodejs8-npm-6.13.4-8.17.0.2.el7.aarch64.rpm
noarch: rh-nodejs8-nodejs-docs-8.17.0-2.el7.noarch.rpm
ppc64le: rh-nodejs8-nodejs-8.17.0-2.el7.ppc64le.rpm rh-nodejs8-nodejs-debuginfo-8.17.0-2.el7.ppc64le.rpm rh-nodejs8-nodejs-devel-8.17.0-2.el7.ppc64le.rpm rh-nodejs8-npm-6.13.4-8.17.0.2.el7.ppc64le.rpm
s390x: rh-nodejs8-nodejs-8.17.0-2.el7.s390x.rpm rh-nodejs8-nodejs-debuginfo-8.17.0-2.el7.s390x.rpm rh-nodejs8-nodejs-devel-8.17.0-2.el7.s390x.rpm rh-nodejs8-npm-6.13.4-8.17.0.2.el7.s390x.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-nodejs8-nodejs-8.17.0-2.el7.src.rpm
aarch64: rh-nodejs8-nodejs-8.17.0-2.el7.aarch64.rpm rh-nodejs8-nodejs-debuginfo-8.17.0-2.el7.aarch64.rpm rh-nodejs8-nodejs-devel-8.17.0-2.el7.aarch64.rpm rh-nodejs8-npm-6.13.4-8.17.0.2.el7.aarch64.rpm
noarch: rh-nodejs8-nodejs-docs-8.17.0-2.el7.noarch.rpm
ppc64le: rh-nodejs8-nodejs-8.17.0-2.el7.ppc64le.rpm rh-nodejs8-nodejs-debuginfo-8.17.0-2.el7.ppc64le.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:2625-01
Product: Red Hat Software Collections
Issue date: 2020-06-18

Topic

An update for rh-nodejs8-nodejs is now available for Red Hat SoftwareCollections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Bugs Fixed

1448380 - CVE-2017-18077 nodejs-brace-expansion: Regular expression denial of service

1567228 - CVE-2018-3737 nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js

1578246 - CVE-2018-3750 nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties

1611613 - CVE-2017-18869 nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js

1788301 - CVE-2019-16777 npm: Global node_modules Binary Overwrite

1788305 - CVE-2019-16775 npm: Symlink reference outside of node_modules folder through the bin field upon installation

1788310 - CVE-2019-16776 npm: Arbitrary file write via constructed entry in the package.json bin field

1829414 - rh-nodejs8: One extra rebuild to deliver the last upstream version

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.