[CLSA-2025:1764933683] alt-nodejs14-nodejs: Fix of CVE-2023-46809
Type:
security
Severity:
Moderate
Release date:
2025-12-05 18:18:02 UTC
Description:
- CVE-2023-46809: fixes a timing‑side‑channel flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style padding‑oracle attack that could allow recovery of sensitive data.
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-11.el9.x86_64.rpm
    sha:a3103f6101f18ea06479cf228eaeee7d8a9dcf54e7279fd01bd37ea952e645cc
  • alt-nodejs14-nodejs-devel-14.21.3-11.el9.x86_64.rpm
    sha:f01a82fbdf52b1e4129ee80e0f9f7f6bfce85308607e2cf4d072c6eba9a71013
  • alt-nodejs14-nodejs-docs-14.21.3-11.el9.noarch.rpm
    sha:a604dd1900dda03d8150601fd868a1fb41c45d295fe69c72a8a8fd2bbb202ba3
  • alt-nodejs14-npm-6.14.18-14.21.3.11.el9.x86_64.rpm
    sha:dd8d9cf4522046f39b03ead768aad56ceafd07224fb0038fd391153db0247f82
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.