[ALPINE:CVE-2021-22918] nodejs vulnerability
Severity
Medium
Affected Packages
30
Fixed Packages
30
CVEs
1
[From CVE-2021-22918] Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
- ID
- ALPINE:CVE-2021-22918
- Severity
- medium
- URL
- https://security.alpinelinux.org/vuln/CVE-2021-22918
- Published
-
2021-07-12T11:15:07
(3 years ago) - Modified
-
2021-07-12T11:15:07
(3 years ago) - Rights
- Alpine Linux Security Team
- Other Advisories
-
- ALAS2-2024-2410
- ALSA-2021:3073
- ALSA-2021:3074
- ALSA-2021:3075
- ASA-202107-13
- ASA-202107-36
- DSA-4936-1
- ELSA-2021-3073
- ELSA-2021-3074
- ELSA-2021-3075
- FREEBSD:C174118E-1B11-11EC-9D9D-0022489AD614
- GLSA-202401-23
- GLSA-202405-29
- MS:CVE-2021-22918
- openSUSE-SU-2021:1059-1
- openSUSE-SU-2021:1060-1
- openSUSE-SU-2021:1061-1
- openSUSE-SU-2021:2327-1
- openSUSE-SU-2021:2353-1
- openSUSE-SU-2021:2354-1
- RHSA-2021:3073
- RHSA-2021:3074
- RHSA-2021:3075
- RLSA-2021:3073
- RLSA-2021:3074
- RLSA-2021:3075
- SUSE-SU-2021:2319-1
- SUSE-SU-2021:2323-1
- SUSE-SU-2021:2326-1
- SUSE-SU-2021:2327-1
- SUSE-SU-2021:2353-1
- SUSE-SU-2021:2354-1
- USN-5007-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | mips64 | |
Affected | pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | mips64 | |
Fixed | pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | mips64 | |
Affected | pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | mips64 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 | alpine | nodejs | = 14.17.3-r0 | alpine-3.14 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 | alpine | nodejs | < 14.17.3-r0 | alpine-3.14 | aarch64 | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 | alpine | nodejs | = 14.17.3-r0 | alpine-3.13 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 | alpine | nodejs | < 14.17.3-r0 | alpine-3.13 | aarch64 | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 | alpine | nodejs | = 12.22.2-r0 | alpine-3.12 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 | alpine | nodejs | < 12.22.2-r0 | alpine-3.12 | aarch64 | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 | alpine | nodejs | = 12.22.2-r0 | alpine-3.11 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 | alpine | nodejs | < 12.22.2-r0 | alpine-3.11 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |