Revision Date: | 2021-12-02 | Version: | 1 |
Title: | Security update for nodejs14 (Important) |
Description: |
This update for nodejs14 fixes the following issues:
nodejs14 was updated to 14.18.1:
deps: update llhttp to 2.1.4
Security fixes:
- HTTP Request Smuggling due to spaced in headers (bsc#1191601, CVE-2021-22959) - HTTP Request Smuggling when parsing the body (bsc#1191602, CVE-2021-22960)
Changes in 14.18.0:
* buffer:
+ introduce Blob + add base64url encoding option
* child_process:
+ allow options.cwd receive a URL + add timeout to spawn and fork + allow promisified exec to be cancel + add 'overlapped' stdio flag
* dns: add 'tries' option to Resolve options * fs:
+ allow empty string for temp directory prefix + allow no-params fsPromises fileHandle read + add support for async iterators to fsPromises.writeFile
* http2: add support for sensitive headers * process: add 'worker' event * tls: allow reading data into a static buffer * worker: add setEnvironmentData/getEnvironmentData
Changes in 14.17.6:
* deps: upgrade npm to 6.14.15 which fixes a number of security issues (bsc#1190057, CVE-2021-37701, bsc#1190056, CVE-2021-37712, bsc#1190055, CVE-2021-37713, bsc#1190054, CVE-2021-39134, bsc#1190053, CVE-2021-39135)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1047218 1050549 1051510 1052904 1053043 1055117 1055121 1061840 1065600 1065729 1070872 1074971 1080978 1081495 1082555 1083647 1084533 1084671 1085535 1085536 1086185 1088804 1092920 1094244 1094680 1095817 1097583 1097584 1097585 1097586 1097587 1097588 1098017 1100132 1101888 1101889 1102522 1103259 1104821 1105000 1106383 1108038 1111331 1112128 1112178 1113313 1113399 1113722 1113978 1114209 1114279 1114542 1114638 1118897 1118898 1118899 1119086 1119634 1119680 1119706 1120318 1120902 1122767 1123105 1124593 1125342 1126221 1126356 1126704 1126740 1127175 1127371 1127372 1127374 1127378 1127445 1128415 1128544 1129276 1129770 1130130 1130154 1130195 1130335 1130336 1130337 1130338 1130425 1130427 1130518 1130527 1130567 1131062 1131107 1131167 1131168 1131169 1131170 1131171 1131172 1131173 1131174 1131175 1131176 1131177 1131178 1131179 1131180 1131290 1131335 1131336 1131416 1131427 1131442 1131467 1131574 1131587 1131659 1131673 1131847 1131848 1131851 1131900 1131934 1131935 1132083 1132219 1132226 1132227 1132365 1132368 1132369 1132370 1132372 1132373 1132384 1132397 1132402 1132403 1132404 1132405 1132407 1132411 1132412 1132413 1132414 1132426 1132527 1132531 1132555 1132558 1132561 1132562 1132563 1132564 1132570 1132571 1132572 1132589 1132618 1132681 1132726 1132828 1132943 1133005 1133094 1133095 1133115 1133149 1133486 1133495 1133529 1133584 1133667 1133668 1133672 1133674 1133675 1133698 1133702 1133731 1133769 1133772 1133774 1133778 1133779 1133780 1133825 1133850 1133851 1133852 1135656 1140709 1141844 1151377 1153095 1153245 1153611 1154256 1155207 1155574 1156213 1156482 1157465 1158485 1158940 1159118 1159814 1159928 1160687 1160931 1161436 1161517 1161521 1162108 1162327 1162504 1165425 1165870 1167463 1171997 1172021 1174628 1175193 1175194 1178067 1190053 1190054 1190055 1190056 1190057 1191601 1191602 CVE-2009-2666 CVE-2010-1167 CVE-2011-1947 CVE-2011-3389 CVE-2012-3482 CVE-2017-0381 CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2018-14394 CVE-2018-14395 CVE-2018-16873 CVE-2018-16874 CVE-2018-16875 CVE-2018-16880 CVE-2018-7187 CVE-2019-11091 CVE-2019-12838 CVE-2019-13616 CVE-2019-17361 CVE-2019-18897 CVE-2019-19956 CVE-2019-20386 CVE-2019-20388 CVE-2019-3882 CVE-2019-7164 CVE-2019-7548 CVE-2019-9003 CVE-2019-9500 CVE-2019-9503 CVE-2020-12801 CVE-2020-14344 CVE-2020-14349 CVE-2020-14350 CVE-2020-1712 CVE-2020-27560 CVE-2020-7595 CVE-2021-22959 CVE-2021-22960 CVE-2021-37701 CVE-2021-37712 CVE-2021-37713 CVE-2021-39134 CVE-2021-39135 SUSE-SU-2018:4297-1 SUSE-SU-2019:1299-1 SUSE-SU-2019:2253-1 SUSE-SU-2019:2989-1 SUSE-SU-2020:0335-1 SUSE-SU-2020:0684-1 SUSE-SU-2020:1299-1 SUSE-SU-2020:2116-1 SUSE-SU-2020:2355-1 SUSE-SU-2020:3162-1 SUSE-SU-2020:3261-1 SUSE-SU-2021:3886-1
|
Platform(s): | openSUSE Leap 15.0 openSUSE Leap 15.1 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Desktop 12 SP1 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1 SUSE Linux Enterprise Module for Basesystem 15 SP1 SUSE Linux Enterprise Module for Basesystem 15 SP2 SUSE Linux Enterprise Module for Containers 15 SUSE Linux Enterprise Module for Desktop Applications 15 SUSE Linux Enterprise Module for Desktop Applications 15 SP1 SUSE Linux Enterprise Module for Desktop Applications 15 SP2 SUSE Linux Enterprise Module for Development Tools 15 SP1 SUSE Linux Enterprise Module for Legacy Software 15 SUSE Linux Enterprise Module for Legacy Software 15 SP1 SUSE Linux Enterprise Module for Legacy Software 15 SP2 SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Module for Live Patching 15 SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 SUSE Linux Enterprise Module for Public Cloud 15 SP1 SUSE Linux Enterprise Module for Python2 packages 15 SP2 SUSE Linux Enterprise Module for Server Applications 15 SUSE Linux Enterprise Module for Server Applications 15 SP1 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Module for Web Scripting 15 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP4 SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12 SP3 SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP5 SUSE Linux Enterprise Server for SAP Applications 15 SUSE Linux Enterprise Workstation Extension 15 SUSE Linux Enterprise Workstation Extension 15 SP1 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.0 is installed AND Package Information
nginx-1.14.2-16 is installed
OR vim-plugin-nginx-1.14.2-16 is installed
|
Definition Synopsis |
openSUSE Leap 15.1 is installed
AND putty-0.72-lp151.3.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP2 is installed
AND Package Information
libpixman-1-0-0.16.0-1.4 is installed
OR libpixman-1-0-32bit-0.16.0-1.4 is installed
OR libpixman-1-0-devel-0.16.0-1.4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP3 is installed
AND Package Information
MozillaFirefox-31.5.3esr-0.8 is installed
OR MozillaFirefox-translations-31.5.3esr-0.8 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP4 is installed
AND Package Information
xen-4.4.4_02-32 is installed
OR xen-doc-html-4.4.4_02-32 is installed
OR xen-kmp-default-4.4.4_02_3.0.101_68-32 is installed
OR xen-kmp-pae-4.4.4_02_3.0.101_68-32 is installed
OR xen-libs-4.4.4_02-32 is installed
OR xen-libs-32bit-4.4.4_02-32 is installed
OR xen-tools-4.4.4_02-32 is installed
OR xen-tools-domU-4.4.4_02-32 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND Package Information
alsa-1.0.27.2-11 is installed
OR libasound2-1.0.27.2-11 is installed
OR libasound2-32bit-1.0.27.2-11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP1 is installed
AND Package Information
libXRes1-1.0.7-3 is installed
OR libXRes1-32bit-1.0.7-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP2 is installed
AND Package Information
alsa-1.0.27.2-11 is installed
OR libasound2-1.0.27.2-11 is installed
OR libasound2-32bit-1.0.27.2-11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
ecryptfs-utils-103-7 is installed
OR ecryptfs-utils-32bit-103-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed
AND Package Information
libwireshark9-2.4.9-48.29 is installed
OR libwiretap7-2.4.9-48.29 is installed
OR libwscodecs1-2.4.9-48.29 is installed
OR libwsutil8-2.4.9-48.29 is installed
OR wireshark-2.4.9-48.29 is installed
OR wireshark-gtk-2.4.9-48.29 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Web Scripting 12 is installed
AND Package Information
nodejs14-14.18.1-6.18.2 is installed
OR nodejs14-devel-14.18.1-6.18.2 is installed
OR nodejs14-docs-14.18.1-6.18.2 is installed
OR npm14-14.18.1-6.18.2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1 is installed
AND Package Information
LibVNCServer-0.9.10-4.14 is installed
OR libvncserver0-0.9.10-4.14 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
AND Package Information
libX11-1.6.5-3.6 is installed
OR libX11-6-1.6.5-3.6 is installed
OR libX11-6-32bit-1.6.5-3.6 is installed
OR libX11-data-1.6.5-3.6 is installed
OR libX11-devel-1.6.5-3.6 is installed
OR libX11-xcb1-1.6.5-3.6 is installed
OR libX11-xcb1-32bit-1.6.5-3.6 is installed
OR libxcb-1.13-3.5 is installed
OR libxcb-composite0-1.13-3.5 is installed
OR libxcb-damage0-1.13-3.5 is installed
OR libxcb-devel-1.13-3.5 is installed
OR libxcb-devel-doc-1.13-3.5 is installed
OR libxcb-dpms0-1.13-3.5 is installed
OR libxcb-dri2-0-1.13-3.5 is installed
OR libxcb-dri2-0-32bit-1.13-3.5 is installed
OR libxcb-dri3-0-1.13-3.5 is installed
OR libxcb-dri3-0-32bit-1.13-3.5 is installed
OR libxcb-glx0-1.13-3.5 is installed
OR libxcb-glx0-32bit-1.13-3.5 is installed
OR libxcb-present0-1.13-3.5 is installed
OR libxcb-present0-32bit-1.13-3.5 is installed
OR libxcb-randr0-1.13-3.5 is installed
OR libxcb-record0-1.13-3.5 is installed
OR libxcb-render0-1.13-3.5 is installed
OR libxcb-res0-1.13-3.5 is installed
OR libxcb-screensaver0-1.13-3.5 is installed
OR libxcb-shape0-1.13-3.5 is installed
OR libxcb-shm0-1.13-3.5 is installed
OR libxcb-sync1-1.13-3.5 is installed
OR libxcb-sync1-32bit-1.13-3.5 is installed
OR libxcb-xf86dri0-1.13-3.5 is installed
OR libxcb-xfixes0-1.13-3.5 is installed
OR libxcb-xfixes0-32bit-1.13-3.5 is installed
OR libxcb-xinerama0-1.13-3.5 is installed
OR libxcb-xinput0-1.13-3.5 is installed
OR libxcb-xkb1-1.13-3.5 is installed
OR libxcb-xtest0-1.13-3.5 is installed
OR libxcb-xv0-1.13-3.5 is installed
OR libxcb-xvmc0-1.13-3.5 is installed
OR libxcb1-1.13-3.5 is installed
OR libxcb1-32bit-1.13-3.5 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
AND postgresql10-10.14-8.19 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Containers 15 is installed
AND Package Information
containerd-1.1.2-5.3 is installed
OR docker-18.06.1_ce-6.8 is installed
OR docker-bash-completion-18.06.1_ce-6.8 is installed
OR docker-libnetwork-0.7.0.1+gitr2664_3ac297bc7fd0-4.3 is installed
OR docker-runc-1.0.0rc5+gitr3562_69663f0bd4b6-6.3 is installed
OR golang-github-docker-libnetwork-0.7.0.1+gitr2664_3ac297bc7fd0-4.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 is installed
AND libopus-devel-1.2.1-1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
AND fetchmailconf-6.3.26-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
AND Package Information
SDL-1.2.15-3.12 is installed
OR libSDL-1_2-0-1.2.15-3.12 is installed
OR libSDL-devel-1.2.15-3.12 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Development Tools 15 SP1 is installed
AND Package Information
ImageMagick-7.0.7.34-3.85 is installed
OR perl-PerlMagick-7.0.7.34-3.85 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Legacy Software 15 is installed
AND Package Information
java-1_8_0-ibm-1.8.0_sr6.0-3.30 is installed
OR java-1_8_0-ibm-alsa-1.8.0_sr6.0-3.30 is installed
OR java-1_8_0-ibm-devel-1.8.0_sr6.0-3.30 is installed
OR java-1_8_0-ibm-plugin-1.8.0_sr6.0-3.30 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Legacy Software 15 SP1 is installed
AND Package Information
kernel-default-4.12.14-197.37 is installed
OR reiserfs-kmp-default-4.12.14-197.37 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Legacy Software 15 SP2 is installed
AND Package Information
java-1_8_0-openjdk-1.8.0.252-3.35 is installed
OR java-1_8_0-openjdk-demo-1.8.0.252-3.35 is installed
OR java-1_8_0-openjdk-devel-1.8.0.252-3.35 is installed
OR java-1_8_0-openjdk-headless-1.8.0.252-3.35 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Live Patching 15 is installed
AND Package Information
kernel-default-4.12.14-25.19 is installed
OR kernel-default-livepatch-4.12.14-25.19 is installed
OR kernel-livepatch-4_12_14-25_19-default-1-1.3 is installed
OR kernel-livepatch-SLE15_Update_5-1-1.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Live Patching 15 SP1 is installed
AND Package Information
kernel-livepatch-4_12_14-195-default-7-19 is installed
OR kernel-livepatch-SLE15-SP1_Update_0-7-19 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 is installed
AND Package Information
kernel-default-4.12.14-150.17 is installed
OR kernel-default-base-4.12.14-150.17 is installed
OR kernel-docs-4.12.14-150.17 is installed
OR kernel-docs-html-4.12.14-150.17 is installed
OR kernel-obs-qa-4.12.14-150.17 is installed
OR kselftests-kmp-default-4.12.14-150.17 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
AND Package Information
python-SQLAlchemy-1.2.14-6.3 is installed
OR python-SQLAlchemy-doc-1.2.14-6.3 is installed
OR python2-SQLAlchemy-1.2.14-6.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
AND Package Information
grub2-2.04-9.7 is installed
OR grub2-arm64-efi-debug-2.04-9.7 is installed
OR grub2-branding-upstream-2.04-9.7 is installed
OR grub2-i386-pc-debug-2.04-9.7 is installed
OR grub2-powerpc-ieee1275-debug-2.04-9.7 is installed
OR grub2-s390x-emu-debug-2.04-9.7 is installed
OR grub2-x86_64-efi-debug-2.04-9.7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Public Cloud 15 SP1 is installed
AND Package Information
kernel-azure-4.12.14-8.41 is installed
OR kernel-azure-base-4.12.14-8.41 is installed
OR kernel-azure-devel-4.12.14-8.41 is installed
OR kernel-devel-azure-4.12.14-8.41 is installed
OR kernel-source-azure-4.12.14-8.41 is installed
OR kernel-syms-azure-4.12.14-8.41 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Python2 packages 15 SP2 is installed
AND mercurial-4.5.2-3.9 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Server Applications 15 is installed
AND Package Information
apache2-2.4.33-3.6 is installed
OR apache2-devel-2.4.33-3.6 is installed
OR apache2-doc-2.4.33-3.6 is installed
OR apache2-prefork-2.4.33-3.6 is installed
OR apache2-utils-2.4.33-3.6 is installed
OR apache2-worker-2.4.33-3.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
AND Package Information
subversion-1.10.6-3.6 is installed
OR subversion-server-1.10.6-3.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Web Scripting 15 is installed
AND Package Information
nodejs8-8.17.0-3.25 is installed
OR nodejs8-devel-8.17.0-3.25 is installed
OR nodejs8-docs-8.17.0-3.25 is installed
OR npm8-8.17.0-3.25 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
accountsservice-0.6.35-3 is installed
OR accountsservice-lang-0.6.35-3 is installed
OR libaccountsservice0-0.6.35-3 is installed
OR typelib-1_0-AccountsService-1_0-0.6.35-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_74-60_64_48-default-4-4 is installed
OR kgraft-patch-3_12_74-60_64_48-xen-4-4 is installed
OR kgraft-patch-SLE12-SP1_Update_17-4-4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND Package Information
fontconfig-2.11.1-7 is installed
OR fontconfig-32bit-2.11.1-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND clamav-0.100.2-33.18 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND Package Information
kgraft-patch-4_4_114-92_67-default-8-2 is installed
OR kgraft-patch-SLE12-SP2_Update_19-8-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
java-1_8_0-openjdk-1.8.0.171-27.19 is installed
OR java-1_8_0-openjdk-demo-1.8.0.171-27.19 is installed
OR java-1_8_0-openjdk-devel-1.8.0.171-27.19 is installed
OR java-1_8_0-openjdk-headless-1.8.0.171-27.19 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
dovecot22-2.2.30.2-14 is installed
OR dovecot22-backend-mysql-2.2.30.2-14 is installed
OR dovecot22-backend-pgsql-2.2.30.2-14 is installed
OR dovecot22-backend-sqlite-2.2.30.2-14 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 15-LTSS is installed
AND Package Information
xen-4.10.4_10-3.31 is installed
OR xen-devel-4.10.4_10-3.31 is installed
OR xen-libs-4.10.4_10-3.31 is installed
OR xen-tools-4.10.4_10-3.31 is installed
OR xen-tools-domU-4.10.4_10-3.31 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 15 is installed
AND Package Information
tomcat-9.0.35-3.57 is installed
OR tomcat-admin-webapps-9.0.35-3.57 is installed
OR tomcat-el-3_0-api-9.0.35-3.57 is installed
OR tomcat-jsp-2_3-api-9.0.35-3.57 is installed
OR tomcat-lib-9.0.35-3.57 is installed
OR tomcat-servlet-4_0-api-9.0.35-3.57 is installed
OR tomcat-webapps-9.0.35-3.57 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 15 is installed
AND enigmail-2.1.2-3.19 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
AND enigmail-2.0.11-3.16 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 6 is installed
AND haproxy-1.5.14-1 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 7 is installed
AND Package Information
java-1_8_0-ibm-1.8.0_sr5.15-30.33 is installed
OR java-1_8_0-ibm-alsa-1.8.0_sr5.15-30.33 is installed
OR java-1_8_0-ibm-devel-1.8.0_sr5.15-30.33 is installed
OR java-1_8_0-ibm-plugin-1.8.0_sr5.15-30.33 is installed
|