Hi,

You are receiving an AlmaLinux Security update email because you subscribed to 
receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2022-11-07

Summary:

Node.js is a software development platform for building fast and scalable 
network applications in the JavaScript programming language. 

Security Fix(es):

* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)

* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)

* c-ares: Missing input validation of host names may lead to domain hijacking 
(CVE-2021-3672)

* nodejs: Improper handling of untypical characters in domain names 
(CVE-2021-22931)

* nodejs-tar: Insufficient symlink protection allowing arbitrary file creation 
and overwrite (CVE-2021-32803)

* nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file 
creation and overwrite (CVE-2021-32804)

* nodejs: Incomplete validation of tls rejectUnauthorized parameter 
(CVE-2021-22939)

* nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe 
(CVE-2021-23343)

For more details about the security issue(s), including the impact, a CVSS 
score, acknowledgments, and other related information, refer to the CVE page(s) 
listed in the References section.

Bug Fix(es):

* nodejs:14/nodejs: Make FIPS options always available (BZ#1993924)

Full details, updated packages, references, and other related information: 
https://errata.almalinux.org/8/ALSA-2021-3666.html

This message is automatically generated, please don’t reply. For further 
questions, please, contact us via the AlmaLinux community chat: 
https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on 
https://lists.almalinux.org.

Kind regards,
AlmaLinux Team

Reply via email to