CVE-2021-22918 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Information disclosure |
| Description | libuv before version 1.14.1, as bundled by Node.js before versions 16.4.1, 14.17.2 and 12.22.2, is vulnerable to an out-of-bounds read in the libuv's uv__idna_toascii() function which is used to convert strings to ASCII. This is called by Node's dns module's lookup() function and can lead to information disclosures or crashes. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2129 | nodejs-lts-dubnium | 10.24.0-2 | High | Unknown | ||
| AVG-2131 | libuv | 1.41.0-1 | 1.41.1-1 | Medium | Fixed | |
| AVG-2128 | nodejs-lts-erbium | 12.22.0-2 | 12.22.3-1 | High | Fixed | |
| AVG-2127 | nodejs-lts-fermium | 14.16.0-2 | 14.17.3-1 | High | Fixed | |
| AVG-2126 | nodejs | 16.4.0-1 | 16.4.1-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 20 Jul 2021 | ASA-202107-36 | AVG-2131 | libuv | Medium | information disclosure |
| 20 Jul 2021 | ASA-202107-33 | AVG-2128 | nodejs-lts-erbium | High | multiple issues |
| 20 Jul 2021 | ASA-202107-32 | AVG-2127 | nodejs-lts-fermium | High | multiple issues |
| 06 Jul 2021 | ASA-202107-13 | AVG-2126 | nodejs | High | multiple issues |