[CLSA-2025:1764605935] Fix CVE(s): CVE-2023-38552
Type:
security
Severity:
Important
Release date:
2025-12-01 16:19:01 UTC
Description:
* SECURITY UPDATE: Node.js policy integrity check bypass vulnerability - debian/patches/CVE-2023-38552.patch: use tamper-proof integrity check function to prevent tampering with Hash class internals in policy mechanism - CVE-2023-38552
Updated packages:
  • alt-nodejs14-docs_14.21.3-9_amd64.deb
    sha:3a84ef137cb130737b7e4c9c0a2e45fada797276
  • alt-nodejs14-nodejs_14.21.3-9_amd64.deb
    sha:370459f72482f6c17a1fe8d0eb485eee2f03ef3d
  • alt-nodejs14-nodejs-devel_14.21.3-9_amd64.deb
    sha:5ae3be063bf59e8e32c21857678284ac35efda3b
  • alt-nodejs14-npm_6.14.18-14.21.3.9_amd64.deb
    sha:e907fc9ff5b2236f7bea731a505156da40ef5f28
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.