[ELSA-2023-3586] nodejs security update
[1:16.19.1-2]
- Update bundled c-ares to 1.19.1
Resolves: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067
[1:16.19.1-1]
- Rebase to 16.19.1
- Resolves: rhbz#2153714
- Resolves: CVE-2023-23918 CVE-2023-23919 CVE-2023-23936 CVE-2023-24807 CVE-2023-23920
- Resolves: CVE-2022-25881 CVE-2022-4904
[1:16.18.1-3]
- Update sources of undici WASM blobs
Resolves: rhbz#2151617
[1:16.18.1-2]
- Add back libs and v8-devel subpackages
- Related: RHBZ#2121126
- Record previously fixed CVE
- Resolves: CVE-2021-44906
[1:16.18.1-1]
- Rebase + CVEs
- Resolves: #2142808
- Resolves: #2142826, #2131745, #2142855
[16.17.1-1]
- Rebase to version 16.17.1
Resolves: CVE-2022-35255 CVE-2022-35256
[16.16.0-1]
- Rebase to version 16.16.0
Resolves: RHBZ#2106290
Resolves: CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215
Resolves: CVE-2022-29244
[16.14.0-5]
- Decouple dependency bundling from bootstrapping
Package | Affected Version |
---|---|
pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 | < 8.19.3-1.16.19.1.2.el9_2 |
pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 | < 16.19.1-2.el9_2 |
pkg:rpm/oraclelinux/nodejs-libs?distro=oraclelinux-9.2 | < 16.19.1-2.el9_2 |
pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 | < 16.19.1-2.el9_2 |
pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 | < 16.19.1-2.el9_2 |
- ID
- ELSA-2023-3586
- Severity
- important
- URL
- https://linux.oracle.com/errata/ELSA-2023-3586.html
- Published
-
2023-06-15T00:00:00
(15 months ago) - Modified
-
2023-06-15T00:00:00
(15 months ago) - Rights
- Copyright 2023 Oracle, Inc.
- Other Advisories
-
- ALAS-2023-1770
- ALAS2-2023-2127
- ALAS2-2024-2399
- ALAS2-2024-2429
- ALSA-2023:3559
- ALSA-2023:3577
- ALSA-2023:3584
- ALSA-2023:3586
- ALSA-2023:4034
- ALSA-2023:4035
- ALSA-2023:6635
- ALSA-2023:7207
- DSA-5419-1
- ELSA-2023-3559
- ELSA-2023-3577
- ELSA-2023-3584
- ELSA-2023-3741
- ELSA-2023-4034
- ELSA-2023-4035
- ELSA-2023-6635
- ELSA-2023-7207
- FEDORA-2023-520848815b
- FEDORA-2023-ae97529c00
- GLSA-202310-09
- MS:CVE-2023-31124
- RHSA-2023:3559
- RHSA-2023:3577
- RHSA-2023:3584
- RHSA-2023:3586
- RHSA-2023:3741
- RHSA-2023:4034
- RHSA-2023:4035
- RHSA-2023:6635
- RHSA-2023:7207
- RLSA-2023:3559
- RLSA-2023:3584
- RLSA-2023:7207
- SSA:2023-142-01
- SUSE-SU-2023:2313-1
- SUSE-SU-2023:2477-1
- SUSE-SU-2023:2655-1
- SUSE-SU-2023:2662-1
- SUSE-SU-2023:2663-1
- SUSE-SU-2023:2669-1
- SUSE-SU-2023:2861-1
- USN-6164-1
- USN-6164-2
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2023-3586 | https://linux.oracle.com/errata/ELSA-2023-3586.html | |
CVE | CVE-2023-31124 | https://linux.oracle.com/cve/CVE-2023-31124.html | |
CVE | CVE-2023-32067 | https://linux.oracle.com/cve/CVE-2023-32067.html | |
CVE | CVE-2023-31147 | https://linux.oracle.com/cve/CVE-2023-31147.html | |
CVE | CVE-2023-31130 | https://linux.oracle.com/cve/CVE-2023-31130.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 | oraclelinux | npm | < 8.19.3-1.16.19.1.2.el9_2 | oraclelinux-9.2 | ||
Affected | pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 | oraclelinux | nodejs | < 16.19.1-2.el9_2 | oraclelinux-9.2 | ||
Affected | pkg:rpm/oraclelinux/nodejs-libs?distro=oraclelinux-9.2 | oraclelinux | nodejs-libs | < 16.19.1-2.el9_2 | oraclelinux-9.2 | ||
Affected | pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 | oraclelinux | nodejs-full-i18n | < 16.19.1-2.el9_2 | oraclelinux-9.2 | ||
Affected | pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 | oraclelinux | nodejs-docs | < 16.19.1-2.el9_2 | oraclelinux-9.2 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |