MGASA-2024-0046

Source
https://advisories.mageia.org/MGASA-2024-0046.html
Import Source
https://advisories.mageia.org/MGASA-2024-0046.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0046
Related
Published
2024-02-22T22:20:27Z
Modified
2024-02-22T22:10:18Z
Summary
Updated nodejs yarnpkg packages fix security vulnerabilities
Details

This is a security release. The following CVEs are fixed in this release: CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High) CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High) CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium) CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium) More detailed information on each of the vulnerabilities can be found in february 2024 Security Releases blog post.

References
Credits

Affected packages

Mageia:9 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.19.1-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / yarnpkg

Package

Name
yarnpkg
Purl
pkg:rpm/mageia/yarnpkg?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.22.21-0.10.2.4.1.mga9

Ecosystem specific

{
    "section": "core"
}