Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple vulnerabilities have been discovered in ISC BIND, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: ISC BIND: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #820563, #835439, #872206 ID: 202210-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in ISC BIND, the worst of which could result in denial of service. Background ========= ISC BIND is the Internet Systems Consortium implementation of the Domain Name System (DNS) protocol. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dns/bind < 9.16.33 > = 9.16.33 2 net-dns/bind-tools < 9.16.33 > = 9.16.33 Description ========== Multiple vulnerabilities have been discovered in ISC BIND. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All ISC BIND users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dns/bind-9.16.33" All ISC BIND-tools users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dns/bind-tools-9.16.33" References ========= [ 1 ] CVE-2021-25219 https://nvd.nist.gov/vuln/detail/CVE-2021-25219 [ 2 ]CVE-2021-25220 https://nvd.nist.gov/vuln/detail/CVE-2021-25220 [ 3 ] CVE-2022-0396 https://nvd.nist.gov/vuln/detail/CVE-2022-0396 [ 4 ] CVE-2022-2795 https://nvd.nist.gov/vuln/detail/CVE-2022-2795 [ 5 ] CVE-2022-2881 https://nvd.nist.gov/vuln/detail/CVE-2022-2881 [ 6 ] CVE-2022-2906 https://nvd.nist.gov/vuln/detail/CVE-2022-2906 [ 7 ] CVE-2022-3080 https://nvd.nist.gov/vuln/detail/CVE-2022-3080 [ 8 ] CVE-2022-38177 https://nvd.nist.gov/vuln/detail/CVE-2022-38177 [ 9 ] CVE-2022-38178 https://nvd.nist.gov/vuln/detail/CVE-2022-38178 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-25 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An issue has been found in c-ares, an asynchronous name resolver. Missing input validation of host names returned by Domain Name Servers can lead to output of wrong hostnames. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2738-1
An update for gupnp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: gupnp security update Advisory ID: RHSA-2021:2417-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2417 Issue date: 2021-06-14 CVE Names: CVE-2021-33516 ==================================================================== 1. Summary: An update for gupnp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: GUPnP is an object-oriented open source framework for creating UPnP devices and control points, written in C using GObject and libsoup. The GUPnP API is intended to be easy to use, efficient and flexible. Security Fix(es): * gupnp: allows DNS rebinding which could result in tricking browser into triggering actions againstlocal UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1964091 - CVE-2021-33516 gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: gupnp-1.0.2-6.el7_9.src.rpm ppc64: gupnp-1.0.2-6.el7_9.ppc.rpm gupnp-1.0.2-6.el7_9.ppc64.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64.rpm ppc64le: gupnp-1.0.2-6.el7_9.ppc64le.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64le.rpm s390x: gupnp-1.0.2-6.el7_9.s390.rpm gupnp-1.0.2-6.el7_9.s390x.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390x.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm ppc64: gupnp-debuginfo-1.0.2-6.el7_9.ppc.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64.rpm gupnp-devel-1.0.2-6.el7_9.ppc.rpm gupnp-devel-1.0.2-6.el7_9.ppc64.rpm ppc64le: gupnp-debuginfo-1.0.2-6.el7_9.ppc64le.rpm gupnp-devel-1.0.2-6.el7_9.ppc64le.rpm s390x: gupnp-debuginfo-1.0.2-6.el7_9.s390.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390x.rpm gupnp-devel-1.0.2-6.el7_9.s390.rpm gupnp-devel-1.0.2-6.el7_9.s390x.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-33516 https://access.redhat.com/security/updates/classification#important 8. Contact: TheRed Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYMfDBtzjgjWX9erEAQh4wA//SuhKPeuUIZWeQkt2mZncTtxzm+gW/IW7 eI0HkcCZ2pAFBHk9RnAOOR4Os3er7+H/jmHpVy/DHzWqzIORZK/2hraQD2+FT7BF QZvLUKqQVUIe4XM1XTKuaQfJ7ObDnWqzKpML1m+wRcdMZjSnh5FRolB/TY2dCadJ 23RdlurPEqdHfzCscguvOX6IQQB+hzL1yEPCveQZZvAbZfqNzJatHlz1My0XJWh1 GVGeGFZea+D85F5WJXvvPbaMTrEBEgfcUDKZ+bI+YJUVyYzNu9mGlihdP0hh2nSw BKOyhTbPtDfCrMTlUtpMS0F3KE+yjrWWfKzdTUWiaHkNvTwa55kWz4LY44z8o/FK 7sjZjWy5cTNdurmWgND997u4FnToPGZRc989TifLg44gHMIDzlO/8BKbcMoXTKIz J1AY+A+POOL8r5BTQX0+tRE1NvxjXCNN1uOA1UshiutM06HhQFJ6wV9v1//1Sj1B QJFtI+WHRr4Gb6dr32wgxnvN+OjOWeA5uoBfn8EY8KUS3PQny7GzJx//Q7L99rVZ tRU1WGrKoo8cXFrfCuDdd3j7TlH6POk+qkUDY8eWoUiqAmxKDGZP177sddmOgK7y 4+6g1G40ex5VnTgZr+GB45b2vVIOGZ9e383BNAsL+TcjnWJKUC92fd+LY+eMhgpV m02U4ORvOnE=6QHR -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2021:1468-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1468 Issue date: 2021-04-29 CVE Names: CVE-2021-25215 ==================================================================== 1. Summary: An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 6 ELS) - i386, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6 ELS) - i386, s390x, x86_64 3. Description: The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): * bind: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself (CVE-2021-25215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, the BIND daemon (named) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1953857 - CVE-2021-25215 bind: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself 6. Package List: Red Hat Enterprise Linux Server (v. 6 ELS): Source: bind-9.8.2-0.68.rc1.el6_10.11.src.rpm i386: bind-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.i686.rpm s390x: bind-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.s390x.rpm x86_64: bind-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6ELS): i386: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.i686.rpm s390x: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.s390x.rpm x86_64: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-25215 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYIqbJ9zjgjWX9erEAQjwPg//SzKTahpLsqjnYf0oNawBZ5PLs39kfn+k SL5o2YzI9klcTQJ9WSz9Ty/vXKw1gHiI31YdSgLDxHayrp4eQIZn+c3vSiQf2mxh cE2qwJZCxfTRv38eOc1zKNWj9e73GJLx9ZQSaPUBB7cRHjIOs0acdkLOHGjZkvOI bjVza/JEw+eLRkJRhk8rxiWn4kjBF5Jyr+ciClySvGcLfGIc95H0rB+pSJhLxoGs 6BknesCQofbfL8jKyUChwbZ0a4CLUYh2EA3u5+KYa+qnwry/Wcy3E5yrWwMFMvV/ BQAJ4YWtQSaK7sRMkEPMMChNO010QdAmqVW7XkA7q1UMo51tsk6yCdxWnA1gbhWc UL2KbjnLv0tfPN/Bi9c4K1gEoiVQaUBKsbkqxKhjd2CQBUN8LhanGsF5n/aJFqzm XGw7nvn/lxiLC0KCIOD2b1ZKUszsR/ELMEWvCOB/VSjAsoVxIK2fsX8oRaTg1Cd+ jB+YlFQAUD64PpnK+RRRZ9GRTihAFvFPO1CHbiw+91nOWr+7HS7AR1BCPGPBmss3 SaerPj40tVSuL/fAH/vVSCviO94yXLZz7w22wGdiSvp8ze7G7yltJVhsUnrz/Wb8 IJc8nKLqhTEXjzvi7hMda2C4ZGzY8vQPGlw0Ns04HNc3zkOk3AXhALmp0D3TdvrF lm/YyuGfPFY=2CXa -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs security update Advisory ID: RHSA-2021:0830-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:0830 Issue date: 2021-03-15 CVE Names: CVE-2021-22883 CVE-2021-22884 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.16.0). Security Fix(es): * nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion (CVE-2021-22883) * nodejs: DNS rebinding in --inspect (CVE-2021-22884) For more details about the securityissue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1932014 - CVE-2021-22883 nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion 1932024 - CVE-2021-22884 nodejs: DNS rebinding in --inspect 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature areavailable from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-22883 https://access.redhat.com/security/cve/CVE-2021-22884 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYE91GtzjgjWX9erEAQgBwg//RHeMzqbG5jkH3mulMlcMywzYaKQHEA77 AvPSPduX7hyXy4VOG4CWZXxoPKb9xibBs1zuDE4JkrWeDv+1+EsijoTfurvYXVRk QpOA4TO3zI0sKuMpEtux4WyEsnj4AcF+7BFNU8yxla0hp5O7OxT1WmJmexW6Qtlv /l54p5OTcSaZdfzW+yEgkZXUi1MpHOllhSDWRolxfHSnU3ZC9MYVfIEFnIoOtpZa wcvpUhS7g7h6f8xl5f3Z58YEFllGvKiKRUl+x/fT7fb1XN0P5yRLywxwwvk0ikci +uAZ3APornOXShEPVbl669kdghmawjP1RbhsUMayfsvNQqY6pjWl8Menk4Z0jYnR UJ2dD1Xv2jCGaQLZEslZ1HQy82GndZ47F2diEr4S4HH5b9wh9EN0aE8XmaCFLfQH uZQCQ1wPh5p/Fq/ZHk9kz5ZoNbBmprpxSZUA6lXBipBYEWjujY28ttLopNUjkZPA YZnitrBvEi+YtVAR0lCc6UVVe/Kq6UfZThrCHSzXmLs/ZfJib0i0lLKXsPd9iTAD UoHsBIlaFqqYmGluU5q3zDAVkjWubzNu/+ehWSAzZYWUKz/XCYoxLy4a+M5yuLZp Y6YUf1e+c8UyQQ2S6+pr7ZaljYdvDZVuA31p+V5YkSWv0cUMfUhdBC/i/EdGwGjs W0DWQFhzzUU=hSAO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f6bd75e9d4 2021-03-12 00:06:28.167832 --------------------------------------------------------------------------------Name : nodejs Product : Fedora 32 Version : 12.21.0 Release : 2.fc32 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. --------------------------------------------------------------------------------Update Information: https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ --------------------------------------------------------------------------------ChangeLog: * Thu Feb 25 2021 Stephen Gallagher - 1:12.21.0-2 - Backport patch to use getauxval * Tue Feb 23 2021 Stephen Gallagher - 1:12.21.0-1 - Update to 12.21.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1932016 - CVE-2021-22883 nodejs:10/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932016 [ 2 ] Bug #1932018 - CVE-2021-22883 nodejs:14/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932018 [ 3 ] Bug #1932019 - CVE-2021-22883 nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932019 [ 4 ] Bug #1932020 - CVE-2021-22883 nodejs:12/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932020 [ 5 ] Bug #1932026 - CVE-2021-22884 nodejs:10/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932026 [ 6 ] Bug #1932028 - CVE-2021-22884 nodejs:14/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932028 [ 7 ] Bug #1932029 - CVE-2021-22884 nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932029 [ 8 ] Bug #1932030 - CVE-2021-22884 nodejs:12/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932030 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f6bd75e9d4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security bug fixed: when links was connected to tor, it would send real dns requests outside the tor network when the displayed page contains link rel="dns-prefetch" code References: . MGASA-2019-0270 - Updated links packages fix security vulnerability Publication date: 12 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0270.html Type: security Affected Mageia releases: 6, 7 Security bug fixed: when links was connected to tor, it would send real dns requests outside the tor network when the displayed page contains link rel="dns-prefetch" code References: - https://bugs.mageia.org/show_bug.cgi?id=25378 - http://links.twibright.com/download/ChangeLog SRPMS: - 7/core/links-2.20-1.mga7 - 6/core/links-2.20-1.mga6 . An advisory has been released regarding Mageia’s links package, focusing on DNS-related vulnerabilities. This applies to both versions 6 and 7, with updates provided to enhance security.. Mageia Security, Links Package Fix, DNS Security Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for ovmf ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0579-1 Rating: important References: #1127820 #1127821 #1127822 Cross-References: CVE-2018-12178 CVE-2018-12180 CVE-2018-3630 Affected Products: SUSE Linux Enterprise Server 12-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for ovmf fixes the following issues: Security issues fixed: - CVE-2018-12180: Fixed a buffer overflow in BlockIo service, which could lead to memory read/write overrun (bsc#1127820). - CVE-2018-12178: Fixed an improper DNS check upon receiving a new DNS packet (bsc#1127821). - CVE-2018-3630: Fixed a logic error in FV parsing which could allow a local attacker to bypass the chain of trust checks (bsc#1127822). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-579=1 Package List: - SUSE Linux Enterprise Server 12-SP3 (aarch64 x86_64): ovmf-2017+git1492060560.b6d11d7c46-4.20.1 ovmf-tools-2017+git1492060560.b6d11d7c46-4.20.1 - SUSE Linux Enterprise Server 12-SP3 (noarch): qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.20.1 qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.20.1 References: https://www.suse.com/security/cve/CVE-2018-12178.html https://www.suse.com/security/cve/CVE-2018-12180.html https://www.suse.com/security/cve/CVE-2018-3630.html https://bugzilla.suse.com/1127820 https://bugzilla.suse.com/1127821 https://bugzilla.suse.com/1127822 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.