[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-243 --- nodejs

ID: oval:org.secpod.oval:def:19500302Date: (C)2024-01-04   (M)2024-02-19
Class: PATCHFamily: unix




A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. It is possible to bypass Permissions and access non authorized modules by using process.mainModule.require. This only affects users who had enabled the experimental permissions option with --experimental-policy

Platform:
Amazon Linux 2023
Product:
nodejs
v8-devel
npm
Reference:
ALAS2023-2023-243
CVE-2022-4904
CVE-2023-23918
CVE    2
CVE-2023-23918
CVE-2022-4904
CPE    2
cpe:/a:npm:npm
cpe:/a:nodejs:nodejs

© SecPod Technologies