Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 21.04 USN-4913-2 Critical: Underscore Code Injection Issue

ubuntu
Calendar Grey April 28, 2021
Dist Ubuntu Esm H88
The recent Underscore patch rectifies a significant security vulnerability in Ubuntu 21.04, providing comprehensive guidance on necessary remediation steps.
Underscore could be made to inject arbitrary code if it received a specially crafted input.

Summary

Underscore could be made to inject arbitrary code if it received a specially

crafted input.

Software Description:

- underscore: Javascript’s functional programming helper library

Details:

USN-4913-1 fixed vulnerabilities in Underscore. This update provides

the corresponding updates for Ubuntu 21.04.

Original advisory details:

It was discovered that Underscore incorrectly handled certain inputs.

An attacker could possibly use this issue to inject arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
  libjs-underscore                1.9.1~dfsg-1ubuntu0.21.04.1
  node-underscore                 1.9.1~dfsg-1ubuntu0.21.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4913-2

https://ubuntu.com/security/notices/USN-4913-1

CVE-2021-23358

Severity
critical
Lowest
Low
Medium
High
Critical

April 28, 2021

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here