Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2020:1568-1 Critical: nodejs10 Denial of Service Fix

suse
Calendar Grey June 9, 2020
Dist Suse Esm H88
SUSE Security Patch for nodejs12 addresses multiple severe vulnerabilities, with setup guidelines provided.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for nodejs10 fixes the following issues: nodejs10 was updated to version 10.21.0 - CVE-2020-8174: Fixed multiple memory corruption in napi_get_value_string_*() (bsc#1172443). - CVE-2020-11080: Fixed a potential denial of service when receiving unreasonably large HTTP/2 SETTINGS frames (bsc#1172442). - CVE-2020-10531: Fixed an integer overflow in UnicodeString:doAppend() (bsc#1166844). - Fixed an issue with openssl by adding getrandom syscall definition for all Linux platforms (bsc#1162117). npm was updated to 6.14.3 - CVE-2020-7598: Fixed an issue which could have tricked minimist into adding or modifying properties of Object.prototype (bsc#1166916). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1162117 #1166844 #1166916 #1172442 #1172443

Cross- CVE-2020-10531 CVE-2020-11080 CVE-2020-7598

CVE-2020-8174

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise Module for Web Scripting 15-SP2

SUSE Linux Enterprise Module for Web Scripting 15-SP1

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-ESPOS

https://www.suse.com/security/cve/CVE-2020-10531.html

https://www.suse.com/security/cve/CVE-2020-11080.html

https://www.suse.com/security/cve/CVE-2020-7598.html

https://www.suse.com/security/cve/CVE-2020-8174.html

https://bugzilla.suse.com/1162117

https://bugzilla.suse.com/1166844

https://bugzilla.suse.com/1166916

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1568-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here