Resource management error in Node.js - CVE-2020-8277
Published: November 19, 2020 / Updated: November 21, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing a large number of DNS responses. A Node.js application that allows an attacker to trigger a DNS request
for a host of their choice could trigger a denial of service condition.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
openEuler
Ubuntu
Fedora
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Automation Manager
BIG-IQ Centralized Management
MySQL Cluster
BIG-IP Advanced WAF
BIG-IP PEM
BIG-IP Analytics
BIG-IP GTM
BIG-IP APM
BIG-IP FPS
BIG-IP ASM
BIG-IP LTM
BIG-IP AFM
BIG-IP Link Controller
BIG-IP DNS
BIG-IP AAM
Dell EMC VxRail Appliance
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
nodejs-current (Alpine package)
nodejs (Alpine package)
libc-ares2 (Ubuntu package)
c-ares-help
c-ares-debuginfo
c-ares-devel
c-ares-debugsource
c-ares
mingw-c-ares
rh-nodejs12-nodejs (Red Hat package)
rh-nodejs14-nodejs (Red Hat package)
Oracle Retail Xstore Point of Service
Storage Defender – Data Protect
Oracle GraalVM Enterprise Edition
How to mitigate CVE-2020-8277
MySQL Cluster - update to 8.0.24
nodejs-current (Alpine package) - update to 15.3.0-r0
nodejs (Alpine package) - update to 14.15.1-r0
Storage Defender – Data Protect - update to 1.4.0
libc-ares2 (Ubuntu package) - update to 1.16.1-1ubuntu0.1
c-ares-help - update to 1.16.1-3
c-ares-debuginfo - update to 1.16.1-3
c-ares-devel - update to 1.16.1-3
c-ares-debugsource - update to 1.16.1-3
c-ares - update to 1.16.1-3
c-ares - addressed in versions 1.17.0-1.fc32, 1.17.0-1.fc33
mingw-c-ares - addressed in versions 1.17.1-1.fc32, 1.17.1-1.fc33
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
Dell EMC VxRail Appliance - update to 7.0.240
rh-nodejs12-nodejs (Red Hat package) - update to 12.19.1-2.el7
rh-nodejs14-nodejs (Red Hat package) - update to 14.15.4-2.el7
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Node.js
- Arch Linux update for c-ares
- Resource management error in nodejs (Alpine package)
- Resource management error in nodejs-current (Alpine package)
- Gentoo update for c-ares
- Gentoo update for NodeJS
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Denial of service in Node.js component in multiple F5 BIG-IP products
- Resource management error in MySQL Cluster
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Denial of service in IBM Watson Assistant for IBM Cloud Pak for Data
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Resource management error in IBM Cloud Automation Manager.
- Resource management error in IBM Cloud Transformation Advisor
- Resource management error in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- openEuler update for c-ares
- Red Hat Software Collections update for rh-nodejs14-nodejs
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Fedora 33 update for mingw-c-ares
- Fedora 32 update for mingw-c-ares
- Ubuntu update for c-ares
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Fedora 32 update for c-ares
- Fedora 33 update for c-ares