[CLSA-2025:1764606602] Fix CVE(s): CVE-2023-38552
Type:
security
Severity:
Important
Release date:
2025-12-01 16:30:06 UTC
Description:
* SECURITY UPDATE: Node.js policy integrity check bypass vulnerability - debian/patches/CVE-2023-38552.patch: use tamper-proof integrity check function to prevent tampering with Hash class internals in policy mechanism - CVE-2023-38552
Updated packages:
  • alt-nodejs14-docs_14.21.3-9_amd64.deb
    sha:de20fa753383ed02bf80c95fced17bfef1d6c968
  • alt-nodejs14-nodejs_14.21.3-9_amd64.deb
    sha:61d6691bc9687c4539f72b9dfe32c43de51ac21e
  • alt-nodejs14-nodejs-devel_14.21.3-9_amd64.deb
    sha:b8bf7f8a9aeab63697c70ef1b24c1cca57aba873
  • alt-nodejs14-npm_6.14.18-14.21.3.9_amd64.deb
    sha:db7b848808af2a4626de7b0478cd97231a30893e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.