[ALPINE:CVE-2021-22918] nodejs vulnerability

Severity Medium
Affected Packages 30
Fixed Packages 30
CVEs 1

[From CVE-2021-22918] Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Package Affected Version
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 < 14.17.3-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 < 12.22.2-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 < 12.22.2-r0
Package Fixed Version
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 = 14.17.3-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 = 12.22.2-r0
pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 = 12.22.2-r0
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 x86_64
Affected pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 x86_64
Fixed pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 x86_64
Affected pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 x86_64
Fixed pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 x86_64
Affected pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 x86_64
Fixed pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 x86_64
Affected pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 x86_64
Fixed pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 x86
Affected pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 x86
Fixed pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 x86
Affected pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 x86
Fixed pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 x86
Affected pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 x86
Fixed pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 x86
Affected pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 x86
Fixed pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 s390x
Affected pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 s390x
Fixed pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 s390x
Affected pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 s390x
Fixed pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 s390x
Affected pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 s390x
Fixed pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 s390x
Affected pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 s390x
Fixed pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 ppc64le
Affected pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 ppc64le
Fixed pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 ppc64le
Affected pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 ppc64le
Fixed pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 ppc64le
Affected pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 ppc64le
Fixed pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 ppc64le
Affected pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 ppc64le
Fixed pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 mips64
Affected pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 mips64
Fixed pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 mips64
Affected pkg:apk/alpine/nodejs?arch=mips64&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 mips64
Fixed pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 armv7
Affected pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 armv7
Fixed pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 armv7
Affected pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 armv7
Fixed pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 armv7
Affected pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 armv7
Fixed pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 armv7
Affected pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 armv7
Fixed pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 armhf
Affected pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 armhf
Fixed pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 armhf
Affected pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 armhf
Fixed pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 armhf
Affected pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 armhf
Fixed pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 armhf
Affected pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 armhf
Fixed pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 alpine nodejs = 14.17.3-r0 alpine-3.14 aarch64
Affected pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.14 alpine nodejs < 14.17.3-r0 alpine-3.14 aarch64
Fixed pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 alpine nodejs = 14.17.3-r0 alpine-3.13 aarch64
Affected pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.13 alpine nodejs < 14.17.3-r0 alpine-3.13 aarch64
Fixed pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 alpine nodejs = 12.22.2-r0 alpine-3.12 aarch64
Affected pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.12 alpine nodejs < 12.22.2-r0 alpine-3.12 aarch64
Fixed pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 alpine nodejs = 12.22.2-r0 alpine-3.11 aarch64
Affected pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.11 alpine nodejs < 12.22.2-r0 alpine-3.11 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...