[USN-5007-1] libuv vulnerability
Severity
Medium
Affected Packages
6
CVEs
1
libuv could be made to crash or expose sensitive information if it received a specially crafted input.
Eric Sesterhenn discovered that libuv incorrectly handled certain strings.
An attacker could possibly use this issue to access sensitive information
or cause a crash.
Package | Affected Version |
---|---|
pkg:deb/ubuntu/libuv1?distro=hirsute | < 1.40.0-1ubuntu0.1 |
pkg:deb/ubuntu/libuv1?distro=groovy | < 1.38.0-2ubuntu2.1 |
pkg:deb/ubuntu/libuv1?distro=focal | < 1.34.2-1ubuntu1.3 |
pkg:deb/ubuntu/libuv1-dev?distro=hirsute | < 1.40.0-1ubuntu0.1 |
pkg:deb/ubuntu/libuv1-dev?distro=groovy | < 1.38.0-2ubuntu2.1 |
pkg:deb/ubuntu/libuv1-dev?distro=focal | < 1.34.2-1ubuntu1.3 |
- ID
- USN-5007-1
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-5007-1
- Published
-
2021-07-07T12:12:42
(3 years ago) - Modified
-
2021-07-07T12:12:42
(3 years ago) - Other Advisories
-
- ALAS2-2024-2410
- ALPINE:CVE-2021-22918
- ALSA-2021:3073
- ALSA-2021:3074
- ALSA-2021:3075
- ASA-202107-13
- ASA-202107-36
- DSA-4936-1
- ELSA-2021-3073
- ELSA-2021-3074
- ELSA-2021-3075
- FREEBSD:C174118E-1B11-11EC-9D9D-0022489AD614
- GLSA-202401-23
- GLSA-202405-29
- MS:CVE-2021-22918
- openSUSE-SU-2021:1059-1
- openSUSE-SU-2021:1060-1
- openSUSE-SU-2021:1061-1
- openSUSE-SU-2021:2327-1
- openSUSE-SU-2021:2353-1
- openSUSE-SU-2021:2354-1
- RHSA-2021:3073
- RHSA-2021:3074
- RHSA-2021:3075
- RLSA-2021:3073
- RLSA-2021:3074
- RLSA-2021:3075
- SUSE-SU-2021:2319-1
- SUSE-SU-2021:2323-1
- SUSE-SU-2021:2326-1
- SUSE-SU-2021:2327-1
- SUSE-SU-2021:2353-1
- SUSE-SU-2021:2354-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/libuv1?distro=hirsute | ubuntu | libuv1 | < 1.40.0-1ubuntu0.1 | hirsute | ||
Affected | pkg:deb/ubuntu/libuv1?distro=groovy | ubuntu | libuv1 | < 1.38.0-2ubuntu2.1 | groovy | ||
Affected | pkg:deb/ubuntu/libuv1?distro=focal | ubuntu | libuv1 | < 1.34.2-1ubuntu1.3 | focal | ||
Affected | pkg:deb/ubuntu/libuv1-dev?distro=hirsute | ubuntu | libuv1-dev | < 1.40.0-1ubuntu0.1 | hirsute | ||
Affected | pkg:deb/ubuntu/libuv1-dev?distro=groovy | ubuntu | libuv1-dev | < 1.38.0-2ubuntu2.1 | groovy | ||
Affected | pkg:deb/ubuntu/libuv1-dev?distro=focal | ubuntu | libuv1-dev | < 1.34.2-1ubuntu1.3 | focal |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |