ALAS2023-2023-243 --- nodejsID: oval:org.secpod.oval:def:19500302 | Date: (C)2024-01-04 (M)2024-02-19 |
Class: PATCH | Family: unix |
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. It is possible to bypass Permissions and access non authorized modules by using process.mainModule.require. This only affects users who had enabled the experimental permissions option with --experimental-policy
Platform: |
Amazon Linux 2023 |
Product: |
nodejs |
v8-devel |
npm |