Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/0A59660B33B72D9854F62B8142C5F337
HistoryMar 22, 2023 - 12:00 a.m.

Security fix for the ALT Linux 10 package node version 16.19.1-alt1

2023-03-2200:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
18
alt linux package
node.js v16.19.1
security fix
cve-2023-23918
cve-2023-23919
cve-2023-23920
cve-2023-23936
cve-2023-24807
openssl
npm 8.19.3
rpmrb script
unix

EPSS

0.002

Percentile

54.3%

16.19.1-alt1 built March 22, 2023 Andrey Cherepanov in task #316988

March 13, 2023 Vitaly Lipatov

- new version 16.19.1 (with rpmrb script)
- CVE-2023-23918: Node.js Permissions policies can be bypassed via process.mainModule (High)
- CVE-2023-23919: Node.js OpenSSL error handling issues in nodejs crypto library (Medium)
- CVE-2023-23920: Node.js insecure loading of ICU data through ICU\_DATA environment variable (Low)
- CVE-2023-23936: Fetch API in Node.js did not protect against CRLF injection in host headers (Medium)
- CVE-2023-24807: Regular Expression Denial of Service in Headers in Node.js fetch API (Low)
- set openssl >= 1.1.1s
- set npm >= 8.19.3