Security update for nodejs16
This update for nodejs16 fixes the following issues: Updated to version 16.17.1: - CVE-2022-32213: Fixed bypass via obs-fold mechanic (bsc#1201325). - CVE-2022-32215: Fixed incorrect Parsing of Multi-line Transfer-Encoding (bsc#1201327). - CVE-2022-35256: Fixed incorrect Parsing of Header Fields (bsc#1203832). - CVE-2022-35255: FIxed weak randomness in WebCrypto keygen (bsc#1203831).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs16 fixes the following issues: Updated to version 16.17.1: - CVE-2022-32213: Fixed bypass via obs-fold mechanic (bsc#1201325). - CVE-2022-32215: Fixed incorrect Parsing of Multi-line Transfer-Encoding (bsc#1201327). - CVE-2022-35256: Fixed incorrect Parsing of Header Fields (bsc#1203832). - CVE-2022-35255: FIxed weak randomness in WebCrypto keygen (bsc#1203831).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1201325
- https://bugzilla.suse.com/1201327
- https://bugzilla.suse.com/1203831
- https://bugzilla.suse.com/1203832
- https://www.suse.com/security/cve/CVE-2022-32213
- https://www.suse.com/security/cve/CVE-2022-32215
- https://www.suse.com/security/cve/CVE-2022-35255
- https://www.suse.com/security/cve/CVE-2022-35256
- https://www.suse.com/support/update/announcement/2022/suse-su-20223615-1/