[FREEBSD:08B553ED-537A-11EB-BE6E-0022489AD614] Node.js -- January 2021 Security Releases

Severity High
Affected Packages 4
CVEs 3

Node.js reports:

  use-after-free in TLSWrap (High) (CVE-2020-8265)
  Affected Node.js versions are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.
  HTTP Request Smuggling in nodejs (Low) (CVE-2020-8287)
  Affected versions of Node.js allow two copies of a header field in a http request. For example, two Transfer-Encoding header fields. In this case Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
  OpenSSL - EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971)
  iThis is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20201208.txt.
Package Affected Version
pkg:freebsd/node14 < 14.15.4
pkg:freebsd/node12 < 12.20.1
pkg:freebsd/node10 < 10.23.1
pkg:freebsd/node < 15.5.1
ID
FREEBSD:08B553ED-537A-11EB-BE6E-0022489AD614
Severity
high
Severity from
CVE-2020-8265
URL
http://vuxml.freebsd.org/freebsd/08b553ed-537a-11eb-be6e-0022489ad614.html
Published
2021-01-04T00:00:00
(3 years ago)
Modified
2021-01-14T00:00:00
(3 years ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/node14 node14 < 14.15.4
Affected pkg:freebsd/node12 node12 < 12.20.1
Affected pkg:freebsd/node10 node10 < 10.23.1
Affected pkg:freebsd/node node < 15.5.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...