Lucene search

K
suseSuseOPENSUSE-SU-2018:1963-1
HistoryJul 14, 2018 - 3:11 a.m.

Security update for nodejs8 (moderate)

2018-07-1403:11:40
lists.opensuse.org
37

0.042 Low

EPSS

Percentile

92.3%

This update for nodejs8 to version 8.11.3 fixes the following issues:

These security issues were fixed:

  • CVE-2018-7167: Calling Buffer.fill() or Buffer.alloc() with some
    parameters could have lead to a hang which could have resulted in a DoS
    (bsc#1097375).
  • CVE-2018-7161: By interacting with the http2 server in a manner that
    triggered a cleanup bug where objects are used in native code after they
    are no longer available an attacker could have caused a denial of
    service (DoS) by causing a node server providing an http2 server to
    crash (bsc#1097404).
  • CVE-2018-1000168: Fixed a denial of service vulnerability by unbundling
    nghttp2 (bsc#1097401)

This update was imported from the SUSE:SLE-15:Update update project.