diff options
author | Salvatore Bonaccorso <carnil@debian.org> | 2020-09-18 14:35:39 +0200 |
---|---|---|
committer | Salvatore Bonaccorso <carnil@debian.org> | 2020-09-18 14:35:39 +0200 |
commit | 35fab08f3ba973191b5824f1277a9545a3994b61 (patch) | |
tree | 703ce7a3ebce6724fe645f6554cc05ffdcde10ae | |
parent | 1aaba1e17e07908cfa0cdee2f463dd320e4fc6aa (diff) |
Add reference for commit in libuv upstream referring to CVE-2020-8252
-rw-r--r-- | data/CVE/2020.list | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/data/CVE/2020.list b/data/CVE/2020.list index b1bf751f70..df32d87e65 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -38753,6 +38753,7 @@ CVE-2020-8252 [fs.realpath.native on may cause buffer overflow] - libuv1 1.39.0-1 NOTE: https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/#fs-realpath-native-on-may-cause-buffer-overflow-medium-cve-2020-8252 NOTE: Debian's version of nodejs uses the shared system library of libuv1 instead of the bundled one + NOTE: https://github.com/libuv/libuv/commit/0e6e8620496dff0eb285589ef1e37a7f407f3ddd CVE-2020-8251 [Denial of Service by resource exhaustion CWE-400 due to unfinished HTTP/1.1 requests] RESERVED - nodejs <not-affected> (Only affects 14.x series) |