MGASA-2023-0264

Source
https://advisories.mageia.org/MGASA-2023-0264.html
Import Source
https://advisories.mageia.org/MGASA-2023-0264.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0264
Related
Published
2023-09-24T22:16:18Z
Modified
2023-09-28T17:25:04Z
Summary
Updated nodejs packages fix security vulnerability
Details

This is a security release. As well, it fixes v8 headers detection (mga#28809)

The following CVEs are fixed in this release: CVE-2023-32002: Policies can be bypassed via Module._load (High) CVE-2023-32006: Policies can be bypassed by module.constructor.createRequire (Medium) CVE-2023-32559: Policies can be bypassed via process.binding (Medium) OpenSSL Security Releases OpenSSL security advisory 14th July. OpenSSL security advisory 19th July. OpenSSL security advisory 31st July

More detailed information on each of the vulnerabilities can be found in August 2023 Security Releases blog post.

References
Credits

Affected packages

Mageia:8 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.17.1-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.17.1-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / yarnpkg

Package

Name
yarnpkg
Purl
pkg:rpm/mageia/yarnpkg?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.22.19-13.mga9

Ecosystem specific

{
    "section": "core"
}