VDB
GCVE-110-MAGEIA-2021-169
GCVE-110-MAGEIA-2021-169
Advisory Published
Updated nodejs-chownr package fixes security vulnerability:
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could
allow a local attacker to trick it into descending into unintended
directories via symlink attacks (CVE-2017-18869).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mageia-xfce-config | 4.16.8.2-1.mga8 (unaffected), 0 (affected) | — |
| Mageia | nodejs-chownr | 1.1.0-1.mga7 (unaffected), 1.1.0-1.mga7 (unaffected), 0 (affected), 0 (affected) | — |
Aliases
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.