Debian: DSA-5638-1: libuv1 security update
Mar10
on March 10, 2024
at 1:56 pm
Posted In: Uncategorized
It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks.
Comment