[ASA-202107-36] libuv: information disclosure
Arch Linux Security Advisory ASA-202107-36 ========================================== Severity: Medium Date : 2021-07-20 CVE-ID : CVE-2021-22918 Package : libuv Type : information disclosure Remote : Yes Link : Summary ======= The package libuv before version 1.41.1-1 is vulnerable to information disclosure. Resolution ========== Upgrade to 1.41.1-1. # pacman -Syu "libuv>=1.41.1-1" The problem has been fixed upstream in version 1.41.1. Workaround ========== None. Description =========== libuv before version 1.14.1, as bundled by Node.js before versions 16.4.1, 14.17.2 and 12.22.2, is vulnerable to an out-of-bounds read in the libuv's uv__idna_toascii() function which is used to convert strings to ASCII. This is called by Node's dns module's lookup() function and can lead to information disclosures or crashes. Impact ====== Attempting to look up a crafted domain name could disclose sensitive information or crash an application using libuv. References ==========