nodejs:10 security update
エラータID: AXSA:2020-281:01
リリース日:
2020/09/07 Monday - 13:13
題名:
nodejs:10 security update
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- nodejs に含まれる ICU (International Components for Unicode) の common/unistr.cpp の
UnicodeString::doAppend() 関数には、整数オーバーフローの問題があり、ヒープベースの
バッファオーバーフローを引き起こす脆弱性があります。(CVE-2020-10531)
一部 CVE の翻訳文は JVN からの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2020-10531
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
追加情報:
N/A
ダウンロード:
SRPMS
- nodejs-10.19.0-2.module+el8+111+a9165546.src.rpm
MD5: 89a5f74a50d395b1425117515ab69587
SHA-256: 512d68fe6b3c3c2e9c253f812f5ff075e065691c82e582447be015a6dc4aa3d9
Size: 28.20 MB - nodejs-nodemon-1.18.3-1.module+el8+111+a9165546.src.rpm
MD5: 6916f571c2934aa3932d135ca1bae70e
SHA-256: 87d8faf45c1ee3eca4439be6f9731d82ed472a499482b986819955780066314d
Size: 1.35 MB - nodejs-packaging-17-2.module+el8+111+a9165546.src.rpm
MD5: 2be856a33c3e5955067da3e7497fec4b
SHA-256: fe260f27256c7b2ca09f2792b79361251790096fb59718b2b6e6f814ab762f0c
Size: 20.47 kB
Asianux Server 8 for x86_64
- nodejs-10.19.0-2.module+el8+111+a9165546.x86_64.rpm
MD5: 94333378a2383e9d34a5d97fe6535096
SHA-256: 53a14e1b8b256c6fdfff08a865d163abde18b17f2682f4d8e9904c0362acefca
Size: 9.00 MB - nodejs-debuginfo-10.19.0-2.module+el8+111+a9165546.x86_64.rpm
MD5: 6cf026981bfd1352231d2b6df6d4c9cf
SHA-256: 42ea9e479fe07cdbcead6055ee59988a59ac1ccc8a6434765e971303e02626b7
Size: 132.14 MB - nodejs-debugsource-10.19.0-2.module+el8+111+a9165546.x86_64.rpm
MD5: e7fb53a044c91849d93151c2a0db2d3c
SHA-256: 8fc02f3739ad3291c7de8121ab74c19a6db98192ec045ae8a4bca54e843624ab
Size: 13.14 MB - nodejs-devel-10.19.0-2.module+el8+111+a9165546.x86_64.rpm
MD5: 1f022a98eb86ca41323fd6eacd8c1046
SHA-256: e0edff1fe08aaa40a97bda3f99d57bb8fe4d0c2961ac2a3cd777f14121524f6f
Size: 11.66 MB - nodejs-devel-debuginfo-10.19.0-2.module+el8+111+a9165546.x86_64.rpm
MD5: d56f3f9a4daf6b4969aa10133e00df32
SHA-256: 2471298ab3bcb34d2a30f3b3faf176fd9c4e949d7f73276cd763b7ffedff176b
Size: 148.81 MB - nodejs-docs-10.19.0-2.module+el8+111+a9165546.noarch.rpm
MD5: 99bff8fbc53ecfb6ede973d9223da9f7
SHA-256: 76a957e54cf4f26f218a9e43f90d7301dbbb5d32fbfd77ca01bfe232ea2c56b5
Size: 3.46 MB - nodejs-nodemon-1.18.3-1.module+el8+111+a9165546.noarch.rpm
MD5: 1d4fdfcc96e0f1d67b7d3b50d305617e
SHA-256: d39336e7784cc57b3007af0bb8a3ece4885ee0530098e53b04fd45527040809d
Size: 963.32 kB - nodejs-packaging-17-2.module+el8+111+a9165546.noarch.rpm
MD5: b95f5eb133d00582cf977901209e0fd2
SHA-256: bbbece1efdd5692ce649815c0e08103dd2de7c8b01a73affa700c6867aec54f9
Size: 18.27 kB - npm-6.13.4-1.10.19.0.2.module+el8+111+a9165546.x86_64.rpm
MD5: be120594f299db28233c78e40493973c
SHA-256: 5f3bb123920561e7aaeda022d96268dc64315cd141dc443c9ea603ab0eba5db0
Size: 3.80 MB