USN-6666-1: libuv vulnerability
28 February 2024
libuv could be made to truncate certain hostnames.
Releases
Packages
- libuv1 - asynchronous event notification library
Details
It was discovered that libuv incorrectly truncated certain hostnames. A
remote attacker could possibly use this issue with specially crafted
hostnames to bypass certain checks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.