AlmaLinux 2314 Published by

A nodejs:14 security and bug fix update has been released for AlmaLinux.



ALSA-2021:3666 Important: nodejs:14 security and bug fix update


Type:
security

Severity:
important

Release date:
2021-09-27

Description
Security Fix(es):
* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)
* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)
* c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)
* nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931)
* nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803)
* nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804)
* nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939)
* nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* nodejs:14/nodejs: Make FIPS options always available (BZ#1993924)

References:
CVE-2021-3672
CVE-2021-22930
CVE-2021-22931
CVE-2021-22939
CVE-2021-22940
CVE-2021-23343
CVE-2021-32803
CVE-2021-32804

Updates packages:
nodejs-14.17.5-1.module_el8.4.0+2536+e2879e58.x86_64.rpm
nodejs-devel-14.17.5-1.module_el8.4.0+2536+e2879e58.x86_64.rpm
nodejs-docs-14.17.5-1.module_el8.4.0+2536+e2879e58.noarch.rpm
nodejs-full-i18n-14.17.5-1.module_el8.4.0+2536+e2879e58.x86_64.rpm
npm-6.14.14-1.14.17.5.1.module_el8.4.0+2536+e2879e58.x86_64.rpm

Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2021:3666 Important: nodejs:14 security and bug fix update