安全公告详情

NS-SA-2025-0245

2025-10-23 19:59:52

简介

important: firefox/nodejs security update

严重级别

important

主题

An update for firefox/nodejs is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

firefox:
nodejs:


Security Fix(es):
firefox: The Mozilla Foundation Security Advisory describes this flaw as: If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant.(CVE-2024-5688)
firefox: bugfix
nodejs: A Regular Expression Denial of Service (ReDoS) vulnerability was found in the cross-spawn package for Node.js. Due to improper input sanitization, an attacker can increase CPU usage and crash the program with a large, specially crafted string.(CVE-2024-21538)
nodejs: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.04B7.

影响组件

  • firefox
  • nodejs

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["firefox-128.10.1-2.zncgsl7.2.x86_64.rpm"],"source":"firefox-128.10.1-2.zncgsl7.2.src.rpm"},{"binary":["nodejs-devel-18.20.2-1.zncgsl7.8.x86_64.rpm","npm-10.5.0-1.18.20.2.1.zncgsl7.8.x86_64.rpm","nodejs-docs-18.20.2-1.zncgsl7.8.noarch.rpm","nodejs-full-i18n-18.20.2-1.zncgsl7.8.x86_64.rpm","nodejs-18.20.2-1.zncgsl7.8.x86_64.rpm"],"source":"nodejs-18.20.2-1.zncgsl7.8.src.rpm"}]}]}

CVE

参考