Advisories ยป MGASA-2015-0186

Updated nodejs packages fix security vulnerabilities

Publication date: 05 May 2015
Modification date: 05 May 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0278

Description

Updated nodejs package fixes security vulnerability:

It was found that libuv does not call setgoups before calling setuid/setgid.
This may potentially allow an attacker to gain elevated privileges
(CVE-2015-0278).

The libuv library is bundled with nodejs, and a fixed version of libuv is
included with nodejs as of version 0.10.37.  The nodejs package has been
updated to version 0.10.38 to fix this issue, as well as several other bugs.
                

References

SRPMS

4/core