RHSA-2023:4039: Important: rh-nodejs14-nodejs security update
Important: rh-nodejs14-nodejs security update
Other sources
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.Security Fix(es): c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) c-ares: Buffer Underwrite in aresinetnetpton() (CVE-2023-31130) c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) c-ares: AutoTools does not set CARESRANDOMFILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4039?
The severity of RHSA-2023:4039 is high.
What is the affected software for RHSA-2023:4039?
The affected software for RHSA-2023:4039 is rh-nodejs14-nodejs, rh-nodejs14-nodejs-debuginfo, rh-nodejs14-nodejs-devel, rh-nodejs14-nodejs-docs, rh-nodejs14-nodejs-full-i18n, rh-nodejs14-npm, Red Hat Software Collections (for RHEL Workstation), Red Hat Software Collections (for RHEL Server for System Z), and Red Hat Software Collections (for RHEL Server for IBM Power LE).
How can I fix RHSA-2023:4039?
To fix RHSA-2023:4039, update the affected software packages to version 14.21.3-4.el7.
Where can I find more information about RHSA-2023:4039?
You can find more information about RHSA-2023:4039 at the following link: [RHSA-2023:4039](https://access.redhat.com/errata/RHSA-2023:4039).