MGASA-2021-0360
Dashboard / Vulnerabilities / MGASA-2021-0360
Summary: Updated libuv packages fix security vulnerability
Details: Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo(). (CVE-2021-22918).
References: https://advisories.mageia.org/MGASA-2021-0360.html, https://bugs.mageia.org/show_bug.cgi?id=29231, https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/, https://www.debian.org/security/2021/dsa-4936, https://ubuntu.com/security/notices/USN-5007-1
Affected packages
Package
Name: libuv
Purl: pkg:rpm/mageia/libuv?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
