Buffer overflow in Node.js - CVE-2020-8174
Published: June 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() functions. A remote attacker can create a specially crafted data to the application, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Opensuse
Ubuntu
MicroSCADA X SYS600
MicroSCADA Pro SYS600
Gateway Station (GWS)
e-mesh EMS
FACTS Control Platform (FCP)
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Oracle Blockchain Platform
nodejs (Alpine package)
nodejs (Debian package)
rh-nodejs10-nodejs (Red Hat package)
nodejs-current (Alpine package)
nodejs-legacy (Ubuntu package)
nodejs-dev (Ubuntu package)
nodejs (Ubuntu package)
libnode-dev (Ubuntu package)
libnode64 (Ubuntu package)
rh-nodejs12-nodejs (Red Hat package)
MySQL Cluster
Oracle Banking Extensibility Workbench
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-8174
MicroSCADA X SYS600 - update to 10.3
MicroSCADA Pro SYS600 - update to 10.3
e-mesh EMS - update to 1.0.1
nodejs (Alpine package) - update to 12.18.3-r0
MySQL Cluster - addressed in versions 7.3.31, 7.5.20, 7.6.16, 8.0.22
nodejs (Debian package) - update to 10.21.0~dfsg-1~deb10u1
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
nodejs-current (Alpine package) - update to 14.4.0-r0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
nodejs-legacy (Ubuntu package) - update to Ubuntu Pro
nodejs-dev (Ubuntu package) - update to Ubuntu Pro
nodejs (Ubuntu package) - addressed in versions Ubuntu Pro, 10.19.0~dfsg-3ubuntu1.1
Red Hat OpenShift Container Platform - update to 4.5.8
libnode-dev (Ubuntu package) - update to 10.19.0~dfsg-3ubuntu1.1
libnode64 (Ubuntu package) - update to 10.19.0~dfsg-3ubuntu1.1
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
Oracle Blockchain Platform - update to 21.1.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Debian update for nodejs
- Red Hat Software Collections update for rh-nodejs10-nodejs
- OpenSUSE Linux update for nodejs8
- Buffer overflow in nodejs (Alpine package)
- Buffer overflow in nodejs-current (Alpine package)
- Multiple vulnerabilities in MySQL Cluster
- Gentoo update for NodeJS
- Multiple vulnerabilities in Oracle Banking Extensibility Workbench
- Multiple vulnerabilities in Hitachi Energy e-mesh EMS
- Multiple vulnerabilities in Oracle Blockchain Platform
- Multiple vulnerabilities in Hitachi Energy MicroSCADA Pro/X SYS600
- Multiple vulnerabilities in Hitachi Energy FACTS Control Platform (FCP)
- Multiple vulnerabilities in Hitachi Energy Gateway Station (GWS)
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Ubuntu update for nodejs
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.5
- Multiple vulnerabilities in IBM Cloud Pak for Automation