VDB

GCVE-110-MAGEIA-2021-169

GCVE-110-MAGEIA-2021-169
Advisory Published
Vulnetix · Advisory published April 2, 2021
Updated nodejs-chownr package fixes security vulnerability: A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks (CVE-2017-18869).

Affected Products

VendorProductVersionsPlatforms
Mageiamageia-xfce-config4.16.8.2-1.mga8 (unaffected), 0 (affected)
Mageianodejs-chownr1.1.0-1.mga7 (unaffected), 1.1.0-1.mga7 (unaffected), 0 (affected), 0 (affected)

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›