USN-6564-1: Node.js vulnerabilities
Hubert Kario discovered that Node.js incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2022-4304) CarpetFuzz, Dawei Wang discovered that Node.js incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-4450) Octavio Galland and Marcel Böhme discovered that Node.js incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-0215) David Benjamin discovered that Node.js incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2023-0286) Hubert Kario and Dmitry Belyavsky discovered that Node.js incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-0401)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6564-1?
The severity of USN-6564-1 is moderate due to potential exposure of sensitive information.
How do I fix USN-6564-1?
To fix USN-6564-1, upgrade to the remedied version 12.22.9~dfsg-1ubuntu3.3 of the affected packages.
What vulnerabilities are addressed in USN-6564-1?
USN-6564-1 addresses CVE-2022-4304 among other vulnerabilities.
Which Ubuntu versions are affected by USN-6564-1?
USN-6564-1 affects Ubuntu 22.04 users using specific versions of Node.js packages.
Who discovered the vulnerability in USN-6564-1?
The vulnerability in USN-6564-1 was discovered by Hubert Kario.