diff options
author | Moritz Muehlenhoff <jmm@debian.org> | 2020-09-18 14:10:34 +0200 |
---|---|---|
committer | Moritz Muehlenhoff <jmm@debian.org> | 2020-09-18 14:10:34 +0200 |
commit | e13e9f03d92b0da78a6528faedb8c9fa61351435 (patch) | |
tree | 58081f308895a3316373fb58d601476a670b5e2f | |
parent | 5908c4b14cf05b34e9088a0d964c86af5320e547 (diff) |
refer to libuv1 for CVE-2020-8252
-rw-r--r-- | data/CVE/list | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/data/CVE/list b/data/CVE/list index 8b51f623c7..9384cf3d82 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -41168,8 +41168,9 @@ CVE-2020-8253 RESERVED CVE-2020-8252 [fs.realpath.native on may cause buffer overflow] RESERVED - - nodejs 12.18.4~dfsg-1 + - libuv1 1.39.0-1 NOTE: https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/#fs-realpath-native-on-may-cause-buffer-overflow-medium-cve-2020-8252 + NOTE: Debian's version of nodejs uses the shared system library of libuv1 instead of the bundled one CVE-2020-8251 [Denial of Service by resource exhaustion CWE-400 due to unfinished HTTP/1.1 requests] RESERVED - nodejs <not-affected> (Only affects 14.x series) |