-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBGT1vF8BEAC2w6Af0VgaEvUzWv6T0qj98y+DqoSm76w3SdXg1rTgR/pX3a9c
tlfnoCZcyeSf+ttUnkha9vyzFfhz0u5IFDehqadQyfBCxemeEA+b1KBhSMGpiuRd
KMwOggQObp7oGdjImQRDT2CfQOWg1KsVk2o4lIuYZNcg8BWSyVlKxXEJ+hKmeDmO
P53rzY7l/gSHaeJ2bpYY5dCw0OLVLb/3QdrPthvYg4zvGzgvVwEKGsocADboqFYk
GuffEuYe1DYOCXbAx6Q59ZP/V7IlIFE9kiUpOAAAf6r/qkVBm3Zj4DtTuTMipsdJ
A6cQvvuMx9Qm37u7fOhosdNczZ2Zt38bLu9Gz2oL9mG0YBCe8Qfgf+pXLc6BKOLB
dwymVtV43cz7vlDOhRojWpsVxggV1FecjJ+cdP4FWAusE11ST60pY/W+y61MLzfs
qy3O3MIoQjXBaEGGTtPiEpVeZL+1v8aJuB5sJLAj56OmgSpcc7NqBHwUgjoeMA4y
87utHUSr4II/Ay1H4xOEZoCE+vIC61G32TwTco3WMhtISSOnRZHsc6GRuBeVr5fq
xEvmmo8lG+u5IgDpakbC/OpDxzemCiYJWCiUgF7X7VnlLLBVyxUMv9P1edursuk1
E2W5sl7RYIiPos23YU/Q66rER/egPX6YmsAr38FcqGYh9ZOauSfmKQ0pDwARAQAB
zVVEYXZpZCBGZXJuYW5kZXogR29uemFsZXogKFNpZ24gKyBlbmNyeXB0IGtleSkg
PGRhdmlkLmZlcm5hbmRlemdvbnphbGV6QGNhbm9uaWNhbC5jb20+wsGUBBMBCgA+
FiEELi4vmPVwZWdpuqdqlvdwxzm8Ws4FAmT1vF8CGwMFCQICKQAFCwkIBwIGFQoJ
CAsCBBYCAwECHgECF4AACgkQlvdwxzm8Ws5bUBAAkWPMosnc2/qqCyLSxkO5ACoT
p527SNCSJU0oQqHghxa7dLQr4NrjMsiNIR3GzVl+IeOR3BvIIwGl3VwQ110dAegX
kQ7jSq6k5bMT9UWJ5O6ju47cxQ1QzYwp5xD1rel8CPouvHHoqIGF0IWB74/BDPRK
7HPsip0P/mQFDaqm/lfxJXE9ZX/nsrqfzQpPMMyChXQbkMYr3Nw5j5AiOwHIZX2c
NksAiziNhzqjK5zPRYLIAwMuFgSyAOoBQamclRbPSNEV5A4D+jOflFy4II636ZEh
gs8+e8ggMb4tCofgolHLOzgzOReClVed6jegQI3rU/YFiyA8oC5pEnTk3qnc6Uzd
Fsrmh8nj2sSElcIf6HL2AITyzbja6MHSbNa5yoVqePQNZySYn+odOHA5TETR8U1p
KGs5oNQvMvWIW+o8t8m+di/a3vwzl9M4HnwCAM513qnv5Bqt/qucedCSFNQvf0Xs
f+2YxWckYC6w0QjJyvR22zYrhd4K87rr6HTu+qeonnivU1ePSc6SMEbvHS8uWgh0
nN+qCxkh4UzqBL2qnkRxB3VGF1peLGPjefmIkGt236B9/xkEcSOD7ZHz9xa00jQx
3tDLTHnelsLvk8gnIaBku0cnMtCo5DUyOH04pKif7uhbPLkNbEy4zyD9ga2hoX5R
gkeELpyDEi6bhMs66z/OwU0EZPW8XwEQAM/loHx2tM4KYXFBrQmsaFlOHFHTrj80
hMWDM4KEXo9+ufaXZnoJFAjo4Dmh+MT4Xcfs1ooowoWlik6nDQ6DwYtk237YwK/f
s4H/SbZ/p3uwdN+vCcXcQm5lUf927iVALCE9jJBwZrfr5EA808elZZzQSCT05lMm
lnHICso+l1qjysReXb6mzFqGGvgRtU9HnvkFKW8dx4W/++VVSJP7tf2aKVcpyWj4
GrS8I+4S6RYDMlUGNky1/fZWZsuJPv0Prv6NqhS/8QbwpI3b0RwK//ZF7ur8KIHE
+fiA8weqxHGQG0pAOZNgCjc5YF9sz4ooMZMhQHKVRknNVcGng6HORaZJkKtZKRHd
kCDo0DrQLiKmlKo8DkZozv9YFVxyoYESAfcxLhnKiaRT/RE6QLt85VUItPl8lEQh
1erCt74VG5UoIW+sE5Lz/xAjwPMK5XUwIZJJHEp/RVRqMzyxoqM0vIexS+CfFn0X
0Ayew3oEL4oguF4NJRb609I25tKFQU/b+AiTvA2DkiZ1hH5yk6kgg4VS21czCDJB
5UoZ8FgGdSP/PN8DQZ50X0A1x2VO83Pje5FhlEUKVs2eKbb48989RNCcYNwHy2lY
Ch3o4HzfS+Zhf2lgljoNJrj/rsSGanMFCmLcLZqQWaNN3I3suuDBr8IZJJiKP/SE
OyoV3lWFnQGhABEBAAHCwXwEGAEKACYWIQQuLi+Y9XBlZ2m6p2qW93DHObxazgUC
ZPW8XwIbDAUJAgIpAAAKCRCW93DHObxazqt5D/938SB3G2m5LzR5aYgBpn3C5arg
O3QO0JHsmzXXzCRZ0f8hPVZPNiuii3UwTX4v4eDcgi8MZnaEmxG0vQosal28Yd6f
jJdwNUv74K68N7xB5kAlwC/jONbAeSmod3EwUq8vKINseV/IzBux/uX3CBwvDpGi
a6v/h0EzuF5HQjguvu7/JSuVxP6y0aJ4gECmOJQMtppSlFBXzD5U6E2X6v6zHvqY
tkgwn00Y9J+V60+vncxAGfSJtcLOceAY2rEmj1bl8rhRCTcacImyh0HKfIST+v9o
Jx+opSyHo1RjhwcbmSoc3U5CGZx+y05H/WceQgett5qOZAGUDZhprTt+j/+scrAR
zZf0zzlpkao8UoergBMYc8iTmJ54/iQSxrk1WjS7OecP45oV7fwBNkQZeZuPITnD
0VP/RPpjd4Qz6eDWaccZPCrS785I0Onylygn5aOktDPU3eOmEhrHMuG+JSjfVqbi
m7jVqPFjWg3Loprmpwa1CGd2039Pa/jWfwh0bxsosSdf09kVj+UvlH4Y85Ve57LU
q9U+cpekCs/VZdL277tiMA2uFvQDSepwmQdBUYxkJSffVfK/cJhzZdY0FjsiVySl
kLVKxp9HzWMCMKaIqdXE+4STZz8/FAE8e3yuEbsXs/pmEtR0MZa8pBwmOvN5CSvG
u/zTgENjjv+UNmNeRA==
=IEGB
-----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE4I1aChuaH07AdH+adlTpHiRAJW0FAmXTjsAACgkQdlTpHiRA
JW04aQ/+Kb4HXLUg16PB0MvWH/1DFSxPxRNdWKzD+iS9Pru45zCFYLaX2mTga42d
S3WhMWLYMNXagIQ0kzGJ/ujJeeYS3zQNaiP0QuIA7LI5JqPT7WQIj22HXJg1hVp2
FjajvnsD3kZSVVrfkbR2m3NhwJTmGo1MiuqPxDUGVu4dVIfZw6Vot8z3dtxpvybE
4uh+3RCWZkNL+F68Pc476ZbPRgvgnBNn1WtqeZWArEkH6V27Vod4eAhsX7WWY/jG
L5v28h9is60Fi3twX/Sy6zY1+LOb6UzjRCjr1qiN2lyffcNpufHBKnsp/3suxpC2
4SrTapOdJJtC5xN7DrloLBEfZi9t9XGzrzJoEkJ1r5J0jDYHWWqdDx8IF0R5Ozda
BPCcwXYMBj63km92TQ+vMIoy/lvJi5mP9pyQ//jjEae3MFQBUXuR4mBMPxSN7+bg
p+DrFCZQ5Mu1Q29Myj7NhJqW5kbQKlwYzS4XECY9dltfd0NCeVcaf+eYqgcym1Ba
PmZ/Uu6UpuXLA/BFuDmnnXK8qjdCKKzZqGQWXlOHvO8++GXHyNTuHM3AckKlnwTB
Y6c7uSPAqB1GGfb+soXhB7LyE0C+2KVO1UbRjStw5KRekyHa9v/aQtPSYP0jidUF
I84ITrAcqkypH5H5p0lKIcAJjMPe6xapGJupVQehU+kxqtyTMMg=
=ZerC
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6643-1
February 19, 2024
node-ip vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS (Available with Ubuntu Pro)
- Ubuntu 20.04 LTS (Available with Ubuntu Pro)
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
Summary:
NPM IP could be made to expose sensitive information over the
network.
Software Description:
- node-ip: IP address utilities for node.js
Details:
Emre Durmaz discovered that NPM IP package incorrectly distinguished
between private and public IP addresses. A remote attacker could
possibly use this issue to perform
Server-Side Request Forgery (SSRF) attacks.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
node-ip 2.0.0+~1.1.0-1ubuntu0.1
Ubuntu 22.04 LTS (Available with Ubuntu Pro):
node-ip 1.1.5+~1.1.0-1ubuntu0.1~esm1
Ubuntu 20.04 LTS (Available with Ubuntu Pro):
node-ip 1.1.5-5ubuntu0.1~esm1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
node-ip 1.1.5-1ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6643-1
CVE-2023-42282
Package Information:
https://launchpad.net/ubuntu/+source/node-ip/2.0.0+~1.1.0-1ubuntu0.1
No comments:
Post a Comment