[CLSA-2025:1765361706] Fix CVE(s): CVE-2023-46809
Type:
security
Severity:
Moderate
Release date:
2025-12-10 10:15:10 UTC
Description:
* SECURITY UPDATE: Marvin Attack vulnerability in Node.js – debian/patches/CVE-2023-46809.patch: fixes a timing‑side‑channel flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style padding‑oracle attack that could allow recovery of sensitive data. – CVE-2023-46809
Updated packages:
  • alt-nodejs16-docs_16.20.2-5_amd64.deb
    sha:99ec56c0c28ca549ce6db60b3ac0e1d7f2f7c8b9
  • alt-nodejs16-nodejs_16.20.2-5_amd64.deb
    sha:6a4337977fe9e251c24426d86da9bf9602e221c2
  • alt-nodejs16-nodejs-devel_16.20.2-5_amd64.deb
    sha:e0ebe2cc1fe18e0d0434a4de4484b9c76eaf0db2
  • alt-nodejs16-npm_8.19.4-16.20.2.5_amd64.deb
    sha:d9a770efc6988f2332d0684ab5a74b9c07bbc1b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.