Joyent Node.js 缓冲区错误漏洞

admin 2024-01-15 01:05:36 YS 来源:ZONE.CI 全球网 0 阅读模式
> Joyent Node.js 缓冲区错误漏洞

Joyent Node.js 缓冲区错误漏洞

CNNVD-ID编号 CNNVD-202006-291 CVE编号 CVE-2020-8174
发布时间 2020-06-03 更新时间 2021-01-27
漏洞类型 缓冲区错误 漏洞来源 N/A
危险等级 高危 威胁类型 远程
厂商 N/A

漏洞介绍

Joyent Node.js是美国Joyent公司的一套建立在Google V8 JavaScript引擎之上的网络应用平台。该平台主要用于构建高度可伸缩的应用程序,以及编写能够处理数万条且同时连接到一个物理机的连接代码。

Joyent Node.js 10.21.0之前版本、12.18.0之前版本和14.4.0之前版本中的‘napi_get_value_string_latin1()’、‘napi_get_value_string_utf8()’和‘napi_get_value_string_utf16()’函数存在缓冲区错误漏洞。远程攻击者可借助特制的数据利用该漏洞损坏内存并执行任意代码。

漏洞补丁

目前厂商已发布升级了Joyent Node.js 缓冲区错误漏洞的补丁,Joyent Node.js 缓冲区错误漏洞的补丁获取链接:

参考网址

来源:GENTOO

链接:https://security.gentoo.org/glsa/202101-07

来源:MISC

链接:https://hackerone.com/reports/784186

来源:CONFIRM

链接:https://security.netapp.com/advisory/ntap-20201023-0003/

来源:MISC

链接:https://www.oracle.com/security-alerts/cpuoct2020.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1982/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cloud-private-is-vulnerable-to-multiple-node-js-vulnerabilities-cve-2020-11080-cve-2020-10531-cve-2020-8172-cve-2020-8174/

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2020-8174

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-potential-vulnerability-with-node-js/

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Node-Core-three-vulnerabilities-32395

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2372/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cloud-pak-for-integration-is-affected-by-multiple-node-js-vulnerabilities/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-app-connect-enterprise-certified-container-is-affected-by-multiple-node-js-vulnerabilities/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/158507/Red-Hat-Security-Advisory-2020-3084-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/158398/Red-Hat-Security-Advisory-2020-2895-01.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-netcool-operations-insight-cloud-native-event-analytics-is-affected-by-a-international-components-for-unicode-icu-for-c-c-vulnerability-cve-2020-10531/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2020-10531-cve-2020-8172-cve-2020-8174-cve-2020-11080/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-planning-analytics-workspace/

来源:www.oracle.com

链接:https://www.oracle.com/security-alerts/cpujan2021.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160892/Gentoo-Linux-Security-Advisory-202101-07.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-version-10-19-0-of-node-js-included-in-ibm-netcool-operations-insight-1-6-0-x-has-several-security-vulnerabilities/

来源:www.nsfocus.net

链接:http://www.nsfocus.net/vulndb/47945

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/158346/Red-Hat-Security-Advisory-2020-2852-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159095/Red-Hat-Security-Advisory-2020-3578-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2488/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-affect-ibm-cloud-pak-for-data-node-js-cve-2020-8172-cve-2020-8174-cve-2020-11080/

来源:www.oracle.com

链接:https://www.oracle.com/security-alerts/cpuoct2020.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-control-cve-2020-8172-cve-2020-8174-cve-2020-11080/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2319/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-in-node-js-affect-ibm-app-connect-enterprise-v11/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3081/

受影响实体

暂无

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202006-291

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0