[FREEBSD:08B553ED-537A-11EB-BE6E-0022489AD614] Node.js -- January 2021 Security Releases
Severity
High
Affected Packages
4
CVEs
3
Node.js reports:
use-after-free in TLSWrap (High) (CVE-2020-8265)
Affected Node.js versions are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.
HTTP Request Smuggling in nodejs (Low) (CVE-2020-8287)
Affected versions of Node.js allow two copies of a header field in a http request. For example, two Transfer-Encoding header fields. In this case Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
OpenSSL - EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971)
iThis is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20201208.txt.
Package | Affected Version |
---|---|
pkg:freebsd/node14 | < 14.15.4 |
pkg:freebsd/node12 | < 12.20.1 |
pkg:freebsd/node10 | < 10.23.1 |
pkg:freebsd/node | < 15.5.1 |
- ID
- FREEBSD:08B553ED-537A-11EB-BE6E-0022489AD614
- Severity
- high
- Severity from
- CVE-2020-8265
- URL
- http://vuxml.freebsd.org/freebsd/08b553ed-537a-11eb-be6e-0022489ad614.html
- Published
-
2021-01-04T00:00:00
(3 years ago) - Modified
-
2021-01-14T00:00:00
(3 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- ALAS-2020-1456
- ALAS2-2020-1573
- ALAS2-2024-2502
- ALPINE:CVE-2020-1971
- ALPINE:CVE-2020-8265
- ALPINE:CVE-2020-8287
- ALSA-2020:5476
- ALSA-2021:0548
- ALSA-2021:0549
- ALSA-2021:0551
- ASA-202012-24
- ASA-202101-16
- DSA-4807-1
- DSA-4826-1
- ELSA-2020-5476
- ELSA-2020-5566
- ELSA-2021-0548
- ELSA-2021-0549
- ELSA-2021-0551
- ELSA-2021-9121
- ELSA-2021-9137
- ELSA-2021-9150
- FEDORA-2020-a31b01e945
- FEDORA-2020-ef1870065a
- FEDORA-2021-d5b2c18fe6
- FEDORA-2021-fb1a136393
- FREEBSD:1D56CFC5-3970-11EB-929D-D4C9EF517024
- FREEBSD:56BA4513-A1BE-11EB-9072-D4C9EF517024
- GLSA-202012-13
- GLSA-202101-07
- MS:CVE-2020-1971
- openSUSE-SU-2020:2223-1
- openSUSE-SU-2020:2236-1
- openSUSE-SU-2020:2245-1
- openSUSE-SU-2020:2269-1
- openSUSE-SU-2021:0064-1
- openSUSE-SU-2021:0065-1
- openSUSE-SU-2021:0066-1
- openSUSE-SU-2021:0082-1
- openSUSE-SU-2021:0195-1
- RHSA-2020:5476
- RHSA-2020:5566
- RHSA-2021:0548
- RHSA-2021:0549
- RHSA-2021:0551
- RLSA-2021:0548
- RLSA-2021:0549
- RLSA-2021:0551
- SECADV-20201208-1
- SUSE-SU-2020:3720-1
- SUSE-SU-2020:3721-1
- SUSE-SU-2020:3722-1
- SUSE-SU-2020:3732-1
- SUSE-SU-2020:3740-1
- SUSE-SU-2020:3762-1
- SUSE-SU-2020:3763-1
- SUSE-SU-2021:0060-1
- SUSE-SU-2021:0061-1
- SUSE-SU-2021:0062-1
- SUSE-SU-2021:0068-1
- SUSE-SU-2021:0082-1
- SUSE-SU-2021:0107-1
- SUSE-SU-2021:0121-1
- SUSE-SU-2021:0224-1
- USN-4662-1
- USN-4745-1
- USN-5563-1
- USN-6380-1
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://nodejs.org/en/blog/vulnerability/january-2021-security-releases/ | ||
FreeBSD VuXML | https://www.openssl.org/news/secadv/20201208.txt |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |