Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1000023

Опубликовано: 20 июн. 2016
Источник: redhat
CVSS3: 5.3
CVSS2: 4.3

Описание

A regular expression denial of service flaw was found in Minimatch. An attacker able to make an application using Minimatch to perform matching using a specially crafted glob pattern could cause the application to consume an excessive amount of CPU.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4fh-messagingNot affected
Red Hat Mobile Application Platform 4mbaasNot affected
Red Hat OpenShift Container Platform 3.2nodejs-acceptsFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Container Platform 3.2nodejs-expressFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Container Platform 3.2nodejs-mime-dbFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Container Platform 3.2nodejs-mime-typesFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Container Platform 3.2nodejs-minimatchFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Container Platform 3.2nodejs-negotiatorFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Enterprise 3.1nodejs-acceptsFixedRHSA-2016:160511.08.2016
Red Hat OpenShift Enterprise 3.1nodejs-expressFixedRHSA-2016:160511.08.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1348509nodejs-minimatch: Regular expression denial-of-service

5.3 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 7 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation duplicate of CVE-2016-10540. Notes: All CVE users should reference CVE-2016-10540 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

5.3 Medium

CVSS3

4.3 Medium

CVSS2