Source: nodejs
Version: 20.19.0+dfsg1-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team < team@security.debian.org>
Hi,
The following vulnerabilities were published for nodejs.
CVE-2025-23165[0]:
| Corrupted pointer in node::fs::ReadFileUtf8(const
| FunctionCallbackInfo<Value>& args) when args[0] is a string
CVE-2025-23166[1]:
| Improper error handling in async cryptographic operations
| crashes process
CVE-2025-23167[2]:
| Improper HTTP header block termination in llhttp
</div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Source: nodejs<br>Version: 20.19.0+dfsg1-1<br>
Le jeu. 15 mai 2025 à 21:51, Salvatore Bonaccorso <carnil@debian.org> a
écrit :
Source: nodejs
Version: 20.19.0+dfsg1-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team < team@security.debian.org>
Hi,
The following vulnerabilities were published for nodejs.
CVE-2025-23165[0]:
| Corrupted pointer in node::fs::ReadFileUtf8(const
| FunctionCallbackInfo<Value>& args) when args[0] is a string
CVE-2025-23166[1]:
| Improper error handling in async cryptographic operations
| crashes process
CVE-2025-23167[2]:
| Improper HTTP header block termination in llhttp
As I read it, it seemed that this affects only llhttp - which is
distributed by node-undici right now ?
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (2 / 14) |
Uptime: | 47:57:51 |
Calls: | 10,397 |
Calls today: | 5 |
Files: | 14,066 |
Messages: | 6,417,282 |
Posted today: | 1 |