Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE: 2020:1623-1 Critical Update: nodejs6 Memory Issues

suse
Calendar Grey June 16, 2020
Dist Suse Esm H88
Urgent SUSE Security Patch for nodejs6 resolves two major security issues. Update immediately to ensure system protection.
An update that fixes two vulnerabilities is now available

Summary

This update for nodejs6 fixes the following issues: - CVE-2020-8174: Fixed multiple memory corruption in napi_get_value_string_*() (bsc#1172443). - CVE-2020-7598: Fixed an issue which could have tricked minimist into adding or modifying properties of Object.prototype (bsc#1166916). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-1623=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-1623=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-1623=1

References

#1166916 #1172443

Cross- CVE-2020-7598 CVE-2020-8174

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2020-7598.html

https://www.suse.com/security/cve/CVE-2020-8174.html

https://bugzilla.suse.com/1166916

https://bugzilla.suse.com/1172443

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1623-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here