[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-226 --- nodejs

ID: oval:org.secpod.oval:def:19500257Date: (C)2024-01-04   (M)2024-02-19
Class: PATCHFamily: unix




In some cases Node.js did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service

Platform:
Amazon Linux 2023
Product:
nodejs
v8-devel
npm
Reference:
ALAS2023-2023-226
CVE-2023-23919
CVE    1
CVE-2023-23919
CPE    2
cpe:/a:npm:npm
cpe:/a:nodejs:nodejs

© SecPod Technologies