[ALAS2-2024-2410] Amazon Linux 2 2017.12 - ALAS2-2024-2410: low priority package update for libuv

Severity Low
Affected Packages 12
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2021-22918:
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/libuv?arch=x86_64&distro=amazonlinux-2 amazonlinux libuv < 1.39.0-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libuv?arch=i686&distro=amazonlinux-2 amazonlinux libuv < 1.39.0-1.amzn2.0.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libuv?arch=aarch64&distro=amazonlinux-2 amazonlinux libuv < 1.39.0-1.amzn2.0.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/libuv-static?arch=x86_64&distro=amazonlinux-2 amazonlinux libuv-static < 1.39.0-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libuv-static?arch=i686&distro=amazonlinux-2 amazonlinux libuv-static < 1.39.0-1.amzn2.0.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libuv-static?arch=aarch64&distro=amazonlinux-2 amazonlinux libuv-static < 1.39.0-1.amzn2.0.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/libuv-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux libuv-devel < 1.39.0-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libuv-devel?arch=i686&distro=amazonlinux-2 amazonlinux libuv-devel < 1.39.0-1.amzn2.0.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libuv-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux libuv-devel < 1.39.0-1.amzn2.0.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/libuv-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux libuv-debuginfo < 1.39.0-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libuv-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux libuv-debuginfo < 1.39.0-1.amzn2.0.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libuv-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux libuv-debuginfo < 1.39.0-1.amzn2.0.1 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...