UbuntuUpdates.org

Package "nodejs"

Name: nodejs

Description:

evented I/O for V8 javascript - runtime executable

Latest version: 12.22.9~dfsg-1ubuntu3.6
Release: jammy (22.04)
Level: updates
Repository: universe
Homepage: https://nodejs.org/

Links


Download "nodejs"


Other versions of "nodejs" in Jammy

Repository Area Version
base universe 12.22.9~dfsg-1ubuntu3
security universe 12.22.9~dfsg-1ubuntu3.6
PPA: Nodejs 14.x 14.21.3-deb-1nodesource1
PPA: Node 16.x 16.20.2-deb-1nodesource1
PPA: Node 20 20.5.1-deb-1nodesource1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 12.22.9~dfsg-1ubuntu3.1 2023-10-30 13:09:44 UTC

  nodejs (12.22.9~dfsg-1ubuntu3.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Remote Code Execution
    - debian/patches/CVE-2022-1292.patch: fixed a remote code execution in
      openssl in nodejs
    - debian/patches/CVE-2022-2068.patch: fixed an arbitrary code execution in
      openssl in nodejs
    - debian/patches/CVE-2022-2097.patch: fixed a memory corruption in openssl
      in nodejs
    - CVE-2022-1292
    - CVE-2022-2068
    - CVE-2022-2097
  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2022-0778.patch: fixed an infinite loop in
      BN_mod_sqrt module
    - CVE-2022-0778

 -- Amir Naseredini <email address hidden> Thu, 26 Oct 2023 18:23:45 +0100

CVE-2022-1292 The c_rehash script does not properly sanitise shell metacharacters to ...
CVE-2022-2068 The c_rehash script allows command injection
CVE-2022-2097 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimi ...
CVE-2022-0778 Infinite loop in BN_mod_sqrt() reachable when parsing certificates



About   -   Send Feedback to @ubuntu_updates