[CLSA-2025:1764865735] Fix CVE(s): CVE-2023-46809
Type:
security
Severity:
Moderate
Release date:
2025-12-04 16:28:59 UTC
Description:
* SECURITY UPDATE: Marvin Attack vulnerability in Node.js – debian/patches/CVE-2023-46809.patch: fixes a timing‑side‑channel flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style padding‑oracle attack that could allow recovery of sensitive data. – CVE-2023-46809
Updated packages:
  • alt-nodejs14-docs_14.21.3-11_amd64.deb
    sha:b16fa4db41167b50806facac72b585a0de9dabcf
  • alt-nodejs14-nodejs_14.21.3-11_amd64.deb
    sha:ff2535b6f845c3977dae0a8cbd91e0736a55d5a5
  • alt-nodejs14-nodejs-devel_14.21.3-11_amd64.deb
    sha:53f2faf159b264712b7f16e9cc1699a5874a0b79
  • alt-nodejs14-npm_6.14.18-14.21.3.11_amd64.deb
    sha:5ecc9874a7110ddf9d1cede15943b8c887ecfcad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.