Oval Definition:oval:org.opensuse.security:def:70346
Revision Date:2021-01-11Version:1
Title:Security update for nodejs10 (Moderate)
Description:

This update for nodejs10 fixes the following issues:

- New upstream LTS version 10.23.1: * CVE-2020-8265: use-after-free in TLSWrap (High) bug in TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits (bsc#1180553) * CVE-2020-8287: HTTP Request Smuggling allow two copies of a header field in a http request. For example, two Transfer-Encoding header fields. In this case Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling (https://cwe.mitre.org/data/definitions/444.html). (bsc#1180554) * CVE-2020-1971: OpenSSL - EDIPARTYNAME NULL pointer de-reference (High) This is a vulnerability in OpenSSL which may be exploited through Node.js. (bsc#1179491)

- New upstream LTS version 10.23.0: * deps: upgrade npm to 6.14.8 * n-api: + create N-API version 7 + expose napi_build_version variable
Family:unixClass:patch
Status:Reference(s):1135350
1148742
1158910
1159740
1179491
1180553
1180554
CVE-2017-18594
CVE-2018-15173
CVE-2020-1971
CVE-2020-8016
CVE-2020-8017
CVE-2020-8265
CVE-2020-8287
SUSE-SU-2019:2425-2
SUSE-SU-2020:1580-2
SUSE-SU-2021:0060-1
Platform(s):SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND nmap-7.70-3.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • texlive-collection-basic-2017.135.svn41616-9.12 is installed
  • OR texlive-collection-bibtexextra-2017.135.svn44385-9.12 is installed
  • OR texlive-collection-binextra-2017.135.svn44515-9.12 is installed
  • OR texlive-collection-context-2017.135.svn42330-9.12 is installed
  • OR texlive-collection-fontsextra-2017.135.svn43356-9.12 is installed
  • OR texlive-collection-fontsrecommended-2017.135.svn35830-9.12 is installed
  • OR texlive-collection-fontutils-2017.135.svn37105-9.12 is installed
  • OR texlive-collection-formatsextra-2017.135.svn44177-9.12 is installed
  • OR texlive-collection-games-2017.135.svn42992-9.12 is installed
  • OR texlive-collection-humanities-2017.135.svn42268-9.12 is installed
  • OR texlive-collection-langarabic-2017.135.svn44496-9.12 is installed
  • OR texlive-collection-langchinese-2017.135.svn42675-9.12 is installed
  • OR texlive-collection-langcjk-2017.135.svn43009-9.12 is installed
  • OR texlive-collection-langcyrillic-2017.135.svn44401-9.12 is installed
  • OR texlive-collection-langczechslovak-2017.135.svn32550-9.12 is installed
  • OR texlive-collection-langenglish-2017.135.svn43650-9.12 is installed
  • OR texlive-collection-langeuropean-2017.135.svn44414-9.12 is installed
  • OR texlive-collection-langfrench-2017.135.svn40375-9.12 is installed
  • OR texlive-collection-langgerman-2017.135.svn42045-9.12 is installed
  • OR texlive-collection-langgreek-2017.135.svn44192-9.12 is installed
  • OR texlive-collection-langitalian-2017.135.svn30372-9.12 is installed
  • OR texlive-collection-langjapanese-2017.135.svn44554-9.12 is installed
  • OR texlive-collection-langkorean-2017.135.svn42106-9.12 is installed
  • OR texlive-collection-langother-2017.135.svn44414-9.12 is installed
  • OR texlive-collection-langpolish-2017.135.svn44371-9.12 is installed
  • OR texlive-collection-langportuguese-2017.135.svn30962-9.12 is installed
  • OR texlive-collection-langspanish-2017.135.svn40587-9.12 is installed
  • OR texlive-collection-latex-2017.135.svn41614-9.12 is installed
  • OR texlive-collection-latexextra-2017.135.svn44544-9.12 is installed
  • OR texlive-collection-latexrecommended-2017.135.svn44177-9.12 is installed
  • OR texlive-collection-luatex-2017.135.svn44500-9.12 is installed
  • OR texlive-collection-mathscience-2017.135.svn44396-9.12 is installed
  • OR texlive-collection-metapost-2017.135.svn44297-9.12 is installed
  • OR texlive-collection-music-2017.135.svn40561-9.12 is installed
  • OR texlive-collection-pictures-2017.135.svn44395-9.12 is installed
  • OR texlive-collection-plaingeneric-2017.135.svn44177-9.12 is installed
  • OR texlive-collection-pstricks-2017.135.svn44460-9.12 is installed
  • OR texlive-collection-publishers-2017.135.svn44485-9.12 is installed
  • OR texlive-collection-xetex-2017.135.svn43059-9.12 is installed
  • OR texlive-devel-2017.135-9.12 is installed
  • OR texlive-extratools-2017.135-9.12 is installed
  • OR texlive-filesystem-2017.135-9.12 is installed
  • OR texlive-scheme-basic-2017.135.svn25923-9.12 is installed
  • OR texlive-scheme-context-2017.135.svn35799-9.12 is installed
  • OR texlive-scheme-full-2017.135.svn44177-9.12 is installed
  • OR texlive-scheme-gust-2017.135.svn44177-9.12 is installed
  • OR texlive-scheme-infraonly-2017.135.svn41515-9.12 is installed
  • OR texlive-scheme-medium-2017.135.svn44177-9.12 is installed
  • OR texlive-scheme-minimal-2017.135.svn13822-9.12 is installed
  • OR texlive-scheme-small-2017.135.svn41825-9.12 is installed
  • OR texlive-scheme-tetex-2017.135.svn44187-9.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • nodejs10-10.23.1-1.30.1 is installed
  • OR nodejs10-devel-10.23.1-1.30.1 is installed
  • OR nodejs10-docs-10.23.1-1.30.1 is installed
  • OR npm10-10.23.1-1.30.1 is installed
  • BACK