Candidate: CVE-2014-7192 PublicDate: 2014-12-11 11:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7192 Description: Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773623 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libv8-3.14: upstream_libv8-3.14: needs-triage precise/esm_libv8-3.14: DNE trusty_libv8-3.14: ignored (out of standard support) trusty/esm_libv8-3.14: DNE xenial_libv8-3.14: ignored (end of standard support, was needed) bionic_libv8-3.14: needed focal_libv8-3.14: DNE groovy_libv8-3.14: DNE hirsute_libv8-3.14: DNE impish_libv8-3.14: DNE jammy_libv8-3.14: DNE devel_libv8-3.14: DNE