From 7856a5c98e8ba50193ab6f06ce27ae05e8d3e1c5 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Fri, 18 Sep 2020 14:35:39 +0200 Subject: Add reference for commit in libuv upstream referring to CVE-2020-8252 --- data/CVE/list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list b/data/CVE/list index 9384cf3d82..78a614fd2d 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -41171,6 +41171,7 @@ CVE-2020-8252 [fs.realpath.native on may cause buffer overflow] - libuv1 1.39.0-1 NOTE: https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/#fs-realpath-native-on-may-cause-buffer-overflow-medium-cve-2020-8252 NOTE: Debian's version of nodejs uses the shared system library of libuv1 instead of the bundled one + NOTE: https://github.com/libuv/libuv/commit/0e6e8620496dff0eb285589ef1e37a7f407f3ddd CVE-2020-8251 [Denial of Service by resource exhaustion CWE-400 due to unfinished HTTP/1.1 requests] RESERVED - nodejs (Only affects 14.x series) -- cgit v1.2.3