rh-nodejs14-nodejs-14.21.3-6.el7

エラータID: AXSA:2024-7617:02

リリース日: 
2024/03/19 Tuesday - 01:01
題名: 
rh-nodejs14-nodejs-14.21.3-6.el7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* rh-nodejs14-nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (CVE-2024-22019)

A Asianux Security Bulletin which addresses further details about this flaw is available in the References section.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-22019
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-nodejs14-nodejs-14.21.3-6.el7.src.rpm
    MD5: d01c292bbcd41184268a2f9c8ecb13f2
    SHA-256: b382eb2dfccec9096417c6f830b776570f6dbfe9f279163b31f7bb18330adb06
    Size: 68.17 MB

Asianux Server 7 for x86_64
  1. rh-nodejs14-nodejs-14.21.3-6.el7.x86_64.rpm
    MD5: 2ad9c38fcc35650baa47fb88d722091b
    SHA-256: 9693b5a50ac8cbddeca2051c84424de9af61583a75c485bd19f469739950b22e
    Size: 17.96 MB
  2. rh-nodejs14-nodejs-devel-14.21.3-6.el7.x86_64.rpm
    MD5: f6f32eba4140b28fef25a505a82ffa94
    SHA-256: be62330bc6bf23f6da153d085821300e8a73112392a050475c84c6dffdb88a9d
    Size: 237.90 kB
  3. rh-nodejs14-nodejs-docs-14.21.3-6.el7.noarch.rpm
    MD5: ff1d97f8f1fe0e549b8d34e23dad8dfa
    SHA-256: 0c5c02e81b631169eefe46fb73dd5769627cccdaf942d619a1c83b157e46c6b8
    Size: 4.11 MB
  4. rh-nodejs14-nodejs-full-i18n-14.21.3-6.el7.x86_64.rpm
    MD5: 6ae5f8812ea90d37234c01d51e6ee12f
    SHA-256: 96484d08a94293dd3e1d56bcd8d4d1984cc1cec949cc8533e2adbfc8d1f30b19
    Size: 7.86 MB
  5. rh-nodejs14-npm-6.14.18-14.21.3.6.el7.x86_64.rpm
    MD5: 72b715caaafb873092a7c9ee9c26c8ee
    SHA-256: d7a276815495fbea59864e702007b3bf357eb959df7cb80e0739d585086b65db
    Size: 4.18 MB