CVE-2023-30590

NameCVE-2023-30590
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1039990

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nodejs (PTS)buster10.24.0~dfsg-1~deb10u1vulnerable
buster (security)10.24.0~dfsg-1~deb10u3vulnerable
bullseye12.22.12~dfsg-1~deb11u3vulnerable
bullseye (security)12.22.12~dfsg-1~deb11u4vulnerable
trixie, sid, bookworm18.13.0+dfsg1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nodejssource(unstable)(unfixed)1039990

Notes

[buster] - nodejs <postponed> (minor issue - Inconsistency Between Implementation and Documented Design)
https://nodejs.org/en/blog/vulnerability/june-2023-security-releases#diffiehellman-do-not-generate-keys-after-setting-a-private-key-medium-cve-2023-30590
Fixed by: https://github.com/nodejs/node/commit/1a5c9284ebce5cd71cf7a3c29759a748c373ac85 (v16.x)

Search for package or bug name: Reporting problems