Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
202

openSUSE Leap 15.2 Security Update: Important Nodejs8 Stream Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1343-1 Rating: important References: #1188917 Cross-References: CVE-2021-22930 CVSS scores: CVE-2021-22930 (SUSE): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: nodejs8 was updated to fix the following security issues: - CVE-2021-22930: http2: fixes use after free on close in stream canceling (bsc#1188917) This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1343=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): nodejs8-8.17.0-lp152.3.17.1 nodejs8-debuginfo-8.17.0-lp152.3.17.1 nodejs8-debugsource-8.17.0-lp152.3.17.1 nodejs8-devel-8.17.0-lp152.3.17.1 npm8-8.17.0-lp152.3.17.1 - openSUSE Leap 15.2 (noarch): nodejs8-docs-8.17.0-lp152.3.17.1 References: https://www.suse.com/security/cve/CVE-2021-22930.html https://bugzilla.suse.com/1188917 . Debian Node.js8 security update addresses CVE-2021-22930. Critical fix released for stable 15.2 version. Immediate action required!. openSUSE Security Update,nodejs8 patch,Leap 15.2 fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 11, 2021 Important OpenSUSE
100

SUSE: 2021:2790-1 Important: Nodejs8 Critical Stream Management

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2790-1 Rating: important References: #1188917 Cross-References: CVE-2021-22930 CVSS scores: CVE-2021-22930 (SUSE): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs8 fixes the following issues: - CVE-2021-22930: http2: fixes use after free on close in stream canceling (bsc#1188917). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2790=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patchSUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2790=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2790=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2790=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-2790=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2790=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2790=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-2790=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2790=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2790=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2790=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2790=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2790=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (ppc64le s390x x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Manager Server 4.0 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Manager Retail Branch Server 4.0 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Manager Proxy 4.0 (x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Manager Proxy 4.0 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise Server for SAP 15 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise Server 15-LTSS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 - SUSE Enterprise Storage 6 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE CaaS Platform 4.0 (noarch): nodejs8-docs-8.17.0-3.50.1 - SUSE CaaS Platform 4.0 (x86_64): nodejs8-8.17.0-3.50.1 nodejs8-debuginfo-8.17.0-3.50.1 nodejs8-debugsource-8.17.0-3.50.1 nodejs8-devel-8.17.0-3.50.1 npm8-8.17.0-3.50.1 References: https://www.suse.com/security/cve/CVE-2021-22930.html https://bugzilla.suse.com/1188917 . Vital Debian patch addresses CVE-2021-22929 in python3.8, bolstering security on multiple versions.. SUSE Update, Nodejs8 Security, Patch Management, Critical Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 20, 2021 Important SuSE
202

openSUSE Leap 15.2: 2021:1113-1 Important Nodejs8 DoS Fix

An update that fixes three vulnerabilities is now available. . openSUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1113-1 Rating: important References: #1184450 #1187976 #1187977 Cross-References: CVE-2020-7774 CVE-2021-23362 CVE-2021-27290 CVSS scores: CVE-2020-7774 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-23362 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-23362 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-27290 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-27290 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs8 fixes the following issues: - update to npm 6.14.13 - CVE-2021-27290: Fixed ssri Regular Expression Denial of Service. (bsc#1187976) - CVE-2021-23362: Fixed hosted-git-info Regular Expression Denial of Service. (bsc#1187977) - CVE-2020-7774: fixes y18n Prototype Pollution. (bsc#1184450) This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1113=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): nodejs8-8.17.0-lp152.3.14.1 nodejs8-debuginfo-8.17.0-lp152.3.14.1 nodejs8-debugsource-8.17.0-lp152.3.14.1 nodejs8-devel-8.17.0-lp152.3.14.1 npm8-8.17.0-lp152.3.14.1 - openSUSE Leap 15.2 (noarch): nodejs8-docs-8.17.0-lp152.3.14.1 References: https://www.suse.com/security/cve/CVE-2020-7774.html https://www.suse.com/security/cve/CVE-2021-23362.html https://www.suse.com/security/cve/CVE-2021-27290.html https://bugzilla.suse.com/1184450 https://bugzilla.suse.com/1187976 https://bugzilla.suse.com/1187977 . Important patch release for openSUSE addressing various vulnerabilities in nodejs8. Ensure your system remains protected with the newest updates and solutions.. openSUSE Update,nodejs security,Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 10, 2021 Important OpenSUSE
202

openSUSE Leap 15.3: 2021:2618-1 Important: Nodejs8 Denial of Service

An update that fixes three vulnerabilities is now available. . openSUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2618-1 Rating: important References: #1184450 #1187976 #1187977 Cross-References: CVE-2020-7774 CVE-2021-23362 CVE-2021-27290 CVSS scores: CVE-2020-7774 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-23362 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-23362 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-27290 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-27290 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs8 fixes the following issues: - update to npm 6.14.13 - CVE-2021-27290: Fixed ssri Regular Expression Denial of Service. (bsc#1187976) - CVE-2021-23362: Fixed hosted-git-info Regular Expression Denial of Service. (bsc#1187977) - CVE-2020-7774: fixes y18n Prototype Pollution. (bsc#1184450) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2618=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-10.12.2 nodejs8-debuginfo-8.17.0-10.12.2 nodejs8-debugsource-8.17.0-10.12.2 nodejs8-devel-8.17.0-10.12.2 npm8-8.17.0-10.12.2 - openSUSE Leap 15.3 (noarch): nodejs8-docs-8.17.0-10.12.2 References: https://www.suse.com/security/cve/CVE-2020-7774.html https://www.suse.com/security/cve/CVE-2021-23362.html https://www.suse.com/security/cve/CVE-2021-27290.html https://bugzilla.suse.com/1184450 https://bugzilla.suse.com/1187976 https://bugzilla.suse.com/1187977 . Important openSUSE patch resolves Denial of Service vulnerabilities in nodejs8 and mitigates prototype pollution threats.. openSUSE Security Update,nodejs8 Denial of Service,nodejs8 prototype pollution,nodejs8 update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 05, 2021 Important OpenSUSE
202

openSUSE Leap 15.2: 2021:0389-1 Moderate: Nodejs8 DNS Rebinding

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0389-1 Rating: moderate References: #1182620 Cross-References: CVE-2021-22884 CVSS scores: CVE-2021-22884 (SUSE): 5.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs8 fixes the following issues: - CVE-2021-22884: DNS rebinding in --inspect (bsc#1182620) This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-389=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): nodejs8-8.17.0-lp152.3.11.1 nodejs8-debuginfo-8.17.0-lp152.3.11.1 nodejs8-debugsource-8.17.0-lp152.3.11.1 nodejs8-devel-8.17.0-lp152.3.11.1 npm8-8.17.0-lp152.3.11.1 - openSUSE Leap 15.2 (noarch): nodejs8-docs-8.17.0-lp152.3.11.1 References: https://www.suse.com/security/cve/CVE-2021-22884.html https://bugzilla.suse.com/1182620 . Fedora security patch for python3 addresses critical buffer overflow issue, enhancing overall protection.. openSUSE Security Update,nodejs8 Threat,DNS Rebinding,Software Patch. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2021 OpenSUSE
100

SUSE: 2021:0686-1 Moderate Nodejs8 DNS Rebinding Security Patch

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0686-1 Rating: moderate References: #1182620 Cross-References: CVE-2021-22884 CVSS scores: CVE-2021-22884 (SUSE): 5.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs8 fixes the following issues: - CVE-2021-22884: DNS rebinding in --inspect (bsc#1182620) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP2: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP2-2021-686=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP2 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-10.9.2 nodejs8-debuginfo-8.17.0-10.9.2 nodejs8-debugsource-8.17.0-10.9.2 nodejs8-devel-8.17.0-10.9.2 npm8-8.17.0-10.9.2 - SUSE Linux Enterprise Module for Web Scripting 15-SP2 (noarch): nodejs8-docs-8.17.0-10.9.2 References: https://www.suse.com/security/cve/CVE-2021-22884.html https://bugzilla.suse.com/1182620 . An update has been released for SUSE nodejs8 to resolve a DNS rebinding vulnerability, classified as moderate severity.. SUSE Nodejs8 Update, Moderate Security Advisory, DNS Patch. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2021 SuSE
202

openSUSE Leap 15.2: openSUSE-SU-2021:0195-1 Moderate: HTTP Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0195-1 Rating: moderate References: #1180554 Cross-References: CVE-2020-8287 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs8 fixes the following issue: - CVE-2020-8287: Fixed an HTTP request smuggling vulnerability (bsc#1180554). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-195=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): nodejs8-8.17.0-lp152.3.8.1 nodejs8-debuginfo-8.17.0-lp152.3.8.1 nodejs8-debugsource-8.17.0-lp152.3.8.1 nodejs8-devel-8.17.0-lp152.3.8.1 npm8-8.17.0-lp152.3.8.1 - openSUSE Leap 15.2 (noarch): nodejs8-docs-8.17.0-lp152.3.8.1 References: https://www.suse.com/security/cve/CVE-2020-8287.html https://bugzilla.suse.com/1180554 . The latest Fedora patch resolves a critical buffer overflow vulnerability in python3, significantly improving software safety.. openSUSE Update,nodejs8 security,HTTP smuggling,system patch. . LinuxSecurity.com Team

Calendar%202 Jan 30, 2021 OpenSUSE
100

SUSE: 2021:0121-1 Moderate: Nodejs8 HTTP Request Smuggling Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0121-1 Rating: moderate References: #1180554 Cross-References: CVE-2020-8287 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nodejs8 fixes the following issue: - CVE-2020-8287: Fixed an HTTP request smuggling vulnerability (bsc#1180554). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP2: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP2-2021-121=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP2 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-10.6.1 nodejs8-debuginfo-8.17.0-10.6.1 nodejs8-debugsource-8.17.0-10.6.1 nodejs8-devel-8.17.0-10.6.1 npm8-8.17.0-10.6.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP2 (noarch): nodejs8-docs-8.17.0-10.6.1 References: https://www.suse.com/security/cve/CVE-2020-8287.html https://bugzilla.suse.com/1180554 . SUSE Security Patch addresses critical HTTP request smuggling vulnerabilities in nodejs8. Immediate update advised for SUSE Linux web development utilities.. SUSE Security Update,nodejs8 HTTP Smuggling,Web Scripting Module. . LinuxSecurity.com Team

Calendar%202 Jan 14, 2021 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200