An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1623-1 Rating: critical References: #1166916 #1172443 Cross-References: CVE-2020-7598 CVE-2020-8174 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nodejs6 fixes the following issues: - CVE-2020-8174: Fixed multiple memory corruption in napi_get_value_string_*() (bsc#1172443). - CVE-2020-7598: Fixed an issue which could have tricked minimist into adding or modifying properties of Object.prototype (bsc#1166916). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-1623=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-1623=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-1623=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-1623=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): nodejs6-6.17.1-11.37.1 nodejs6-debuginfo-6.17.1-11.37.1 nodejs6-debugsource-6.17.1-11.37.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): nodejs6-6.17.1-11.37.1 nodejs6-debuginfo-6.17.1-11.37.1 nodejs6-debugsource-6.17.1-11.37.1 - SUSEOpenStack Cloud 7 (aarch64 s390x x86_64): nodejs6-6.17.1-11.37.1 nodejs6-debuginfo-6.17.1-11.37.1 nodejs6-debugsource-6.17.1-11.37.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs6-6.17.1-11.37.1 nodejs6-debuginfo-6.17.1-11.37.1 nodejs6-debugsource-6.17.1-11.37.1 nodejs6-devel-6.17.1-11.37.1 npm6-6.17.1-11.37.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs6-docs-6.17.1-11.37.1 References: https://www.suse.com/security/cve/CVE-2020-7598.html https://www.suse.com/security/cve/CVE-2020-8174.html https://bugzilla.suse.com/1166916 https://bugzilla.suse.com/1172443 _______________________________________________ sle-security-updates mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0488-1 Rating: important References: #1163102 #1163103 #1163104 Cross-References: CVE-2019-15604 CVE-2019-15605 CVE-2019-15606 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs6 fixes the following issues: Security issues fixed: - CVE-2019-15604: Fixed a remotely triggerable assertion in the TLS server via a crafted certificate string (CVE-2019-15604, bsc#1163104). - CVE-2019-15605: Fixed an HTTP request smuggling vulnerability via malformed Transfer-Encoding header (CVE-2019-15605, bsc#1163102). - CVE-2019-15606: Fixed the white space sanitation of HTTP headers (CVE-2019-15606, bsc#1163103). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-488=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-488=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-488=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-488=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): nodejs6-6.17.1-11.33.1 nodejs6-debuginfo-6.17.1-11.33.1 nodejs6-debugsource-6.17.1-11.33.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): nodejs6-6.17.1-11.33.1 nodejs6-debuginfo-6.17.1-11.33.1 nodejs6-debugsource-6.17.1-11.33.1 - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): nodejs6-6.17.1-11.33.1 nodejs6-debuginfo-6.17.1-11.33.1 nodejs6-debugsource-6.17.1-11.33.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs6-6.17.1-11.33.1 nodejs6-debuginfo-6.17.1-11.33.1 nodejs6-debugsource-6.17.1-11.33.1 nodejs6-devel-6.17.1-11.33.1 npm6-6.17.1-11.33.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs6-docs-6.17.1-11.33.1 References: https://www.suse.com/security/cve/CVE-2019-15604.html https://www.suse.com/security/cve/CVE-2019-15605.html https://www.suse.com/security/cve/CVE-2019-15606.html https://bugzilla.suse.com/1163102 https://bugzilla.suse.com/1163103 https://bugzilla.suse.com/1163104 _______________________________________________ sle-security-updates mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0247-1 Rating: important References: #1159352 Cross-References: CVE-2019-16775 CVE-2019-16776 CVE-2019-16777 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs6 to version 6.17.1 fixes the following issues: Security issues fixed: - CVE-2019-16777, CVE-2019-16776, CVE-2019-16775: Updated npm to 6.13.4, fixing an arbitrary path overwrite and access via "bin" field (bsc#1159352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-247=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-247=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-247=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-247=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): nodejs6-6.17.1-11.30.1 nodejs6-debuginfo-6.17.1-11.30.1 nodejs6-debugsource-6.17.1-11.30.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): nodejs6-6.17.1-11.30.1 nodejs6-debuginfo-6.17.1-11.30.1 nodejs6-debugsource-6.17.1-11.30.1 - SUSE OpenStackCloud 7 (aarch64 s390x x86_64): nodejs6-6.17.1-11.30.1 nodejs6-debuginfo-6.17.1-11.30.1 nodejs6-debugsource-6.17.1-11.30.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs6-6.17.1-11.30.1 nodejs6-debuginfo-6.17.1-11.30.1 nodejs6-debugsource-6.17.1-11.30.1 nodejs6-devel-6.17.1-11.30.1 npm6-6.17.1-11.30.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs6-docs-6.17.1-11.30.1 References: https://www.suse.com/security/cve/CVE-2019-16775.html https://www.suse.com/security/cve/CVE-2019-16776.html https://www.suse.com/security/cve/CVE-2019-16777.html https://bugzilla.suse.com/1159352 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2181-1 Rating: important References: #1140290 Cross-References: CVE-2019-13173 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs6 fixes the following issues: - CVE-2019-13173: Fixed a potential file overwrite via hardlink in fstream.DirWriter() (bsc#1140290). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-2181=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2181=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-2181=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2019-2181=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2181=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): nodejs6-6.17.0-11.27.1 nodejs6-debuginfo-6.17.0-11.27.1 nodejs6-debugsource-6.17.0-11.27.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): nodejs6-6.17.0-11.27.1 nodejs6-debuginfo-6.17.0-11.27.1 nodejs6-debugsource-6.17.0-11.27.1 - SUSE OpenStack Cloud 7 (aarch64 s390xx86_64): nodejs6-6.17.0-11.27.1 nodejs6-debuginfo-6.17.0-11.27.1 nodejs6-debugsource-6.17.0-11.27.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs6-6.17.0-11.27.1 nodejs6-debuginfo-6.17.0-11.27.1 nodejs6-debugsource-6.17.0-11.27.1 nodejs6-devel-6.17.0-11.27.1 npm6-6.17.0-11.27.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs6-docs-6.17.0-11.27.1 - SUSE Enterprise Storage 4 (aarch64 x86_64): nodejs6-6.17.0-11.27.1 nodejs6-debuginfo-6.17.0-11.27.1 nodejs6-debugsource-6.17.0-11.27.1 References: https://www.suse.com/security/cve/CVE-2019-13173.html https://bugzilla.suse.com/1140290 _______________________________________________ sle-security-updates mailing list
An update that fixes 7 vulnerabilities is now available. . SUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0395-1 Rating: important References: #1113534 #1113652 #1117625 #1117626 #1117627 #1117629 #1117630 Cross-References: CVE-2018-0734 CVE-2018-12116 CVE-2018-12120 CVE-2018-12121 CVE-2018-12122 CVE-2018-12123 CVE-2018-5407 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for nodejs6 to version 6.16.0 fixes the following issues: Security issues fixed: - CVE-2018-0734: Fixed a timing vulnerability in the DSA signature generation (bsc#1113652) - CVE-2018-5407: Fixed a hyperthread port content side channel attack (aka "PortSmash") (bsc#1113534) - CVE-2018-12120: Fixed that the debugger listens on any interface by default (bsc#1117625) - CVE-2018-12121: Fixed a denial of Service with large HTTP headers (bsc#1117626) - CVE-2018-12122: Fixed the "Slowloris" HTTP Denial of Service (bsc#1117627) - CVE-2018-12116: Fixed HTTP request splitting (bsc#1117630) - CVE-2018-12123: Fixed hostname spoofing in URL parser for javascript protocol (bsc#1117629) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-395=1 - SUSE OpenStack Cloud 7: zypper in -tpatch SUSE-OpenStack-Cloud-7-2019-395=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2019-395=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-395=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): nodejs6-6.16.0-11.21.1 nodejs6-debuginfo-6.16.0-11.21.1 nodejs6-debugsource-6.16.0-11.21.1 - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): nodejs6-6.16.0-11.21.1 nodejs6-debuginfo-6.16.0-11.21.1 nodejs6-debugsource-6.16.0-11.21.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs6-6.16.0-11.21.1 nodejs6-debuginfo-6.16.0-11.21.1 nodejs6-debugsource-6.16.0-11.21.1 nodejs6-devel-6.16.0-11.21.1 npm6-6.16.0-11.21.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs6-docs-6.16.0-11.21.1 - SUSE Enterprise Storage 4 (aarch64 x86_64): nodejs6-6.16.0-11.21.1 nodejs6-debuginfo-6.16.0-11.21.1 nodejs6-debugsource-6.16.0-11.21.1 References: https://www.suse.com/security/cve/CVE-2018-0734.html https://www.suse.com/security/cve/CVE-2018-12116.html https://www.suse.com/security/cve/CVE-2018-12120.html https://www.suse.com/security/cve/CVE-2018-12121.html https://www.suse.com/security/cve/CVE-2018-12122.html https://www.suse.com/security/cve/CVE-2018-12123.html https://www.suse.com/security/cve/CVE-2018-5407.html https://bugzilla.suse.com/1113534 https://bugzilla.suse.com/1113652 https://bugzilla.suse.com/1117625 https://bugzilla.suse.com/1117626 https://bugzilla.suse.com/1117627 https://bugzilla.suse.com/1117629 https://bugzilla.suse.com/1117630 _______________________________________________ sle-security-updates mailing list
An update that solves two vulnerabilities and has one errata is now available.. openSUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2816-1 Rating: moderate References: #1097158 #1097748 #1105019 Cross-References: CVE-2018-0732 CVE-2018-12115 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for nodejs6 to version 6.14.4 fixes the following issues: Security issues fixed: CVE-2018-12115: Fixed an out-of-bounds (OOB) write in Buffer.write() for UCS-2 encoding (bsc#1105019) CVE-2018-0732: Upgrade to OpenSSL 1.0.2p, fixing a client DoS due to large DH parameter (bsc#1097158) Other issues fixed: - Recommend same major version npm package (bsc#1097748) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1041=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): nodejs6-6.14.4-15.1 nodejs6-debuginfo-6.14.4-15.1 nodejs6-debugsource-6.14.4-15.1 nodejs6-devel-6.14.4-15.1 npm6-6.14.4-15.1 - openSUSE Leap 42.3 (noarch): nodejs6-docs-6.14.4-15.1 References: https://www.suse.com/security/cve/CVE-2018-0732.html https://www.suse.com/security/cve/CVE-2018-12115.html https://bugzilla.suse.com/show_bug.cgi?id=1097158 https://bugzilla.suse.com/show_bug.cgi?id=1097748 https://bugzilla.suse.com/show_bug.cgi?id=1105019 -- . A security patch for nodejs6 on openSUSE addresses two severevulnerabilities along with straightforward installation instructions.. openSUSE NodeJS Update, Security Fixes, Software Patching. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for nodejs6 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1962-1 Rating: moderate References: #1091764 #1097375 Cross-References: CVE-2018-7167 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for nodejs6 to version 6.14.3 fixes the following issues: The following security vulnerability was addressed: - Fixed a denial of service (DoS) vulnerability in Buffer.fill(), which could hang when being called (CVE-2018-7167, bsc#1097375). The following other changes were made: - Use absolute paths in executable shebang lines - Fixed building with ICU61.1 (bsc#1091764) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-723=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): nodejs6-6.14.3-12.1 nodejs6-debuginfo-6.14.3-12.1 nodejs6-debugsource-6.14.3-12.1 nodejs6-devel-6.14.3-12.1 npm6-6.14.3-12.1 - openSUSE Leap 42.3 (noarch): nodejs6-docs-6.14.3-12.1 References: https://www.suse.com/security/cve/CVE-2018-7167.html https://bugzilla.suse.com/1091764 https://bugzilla.suse.com/1097375 -- . An important security patch released for nodejs6 on openSUSE, resolving a moderate denial of service vulnerability through an essential update.. OpenSUSE Security Update, NodeJS6 Fix, Denial of Service, Server Protection. .LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.