[CLSA-2025:1765365292] alt-nodejs16-nodejs: Fix of CVE-2023-46809
Type:
security
Severity:
Moderate
Release date:
2025-12-10 11:14:56 UTC
Description:
- CVE-2023-46809: fixes a timing‑side‑channel flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style padding‑oracle attack that could allow recovery of sensitive data.
Updated packages:
  • alt-nodejs16-nodejs-16.20.2-4.el7.x86_64.rpm
    sha:b0d200c138b793d3c8f02ec7824be1126b83eec80e5b4e8e184ab7c030832b4d
  • alt-nodejs16-nodejs-devel-16.20.2-4.el7.x86_64.rpm
    sha:f911ea11218848fcb601790dd5e21a561c16154ad522797f5c340207f7a053b6
  • alt-nodejs16-nodejs-docs-16.20.2-4.el7.noarch.rpm
    sha:cbf7524e54fe6fceb76200d92b8d3522023442b8b937e92589aa994d488d14cc
  • alt-nodejs16-npm-8.19.4-16.20.2.4.el7.x86_64.rpm
    sha:21eff49c1cde67fff073b326f4bd39ef53a47f782289a578b8316db0454195b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.