Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2470-1

Опубликовано: 06 окт. 2016
Источник: suse-cvrf

Описание

Security update for nodejs4

This update brings the new upstream nodejs LTS version 4.6.0, fixing bugs and security issues:

  • Nodejs embedded openssl version update
    • upgrade to 1.0.2j (CVE-2016-6304, CVE-2016-2183, CVE-2016-2178, CVE-2016-6306, CVE-2016-7052)
    • remove support for dynamic 3rd party engine modules
  • http: Properly validate for allowable characters in input user data. This introduces a new case where throw may occur when configuring HTTP responses, users should already be adopting try/catch here. (CVE-2016-5325, bsc#985201)
  • tls: properly validate wildcard certificates (CVE-2016-7099, bsc#1001652)
  • buffer: Zero-fill excess bytes in new Buffer objects created with Buffer.concat()

Список пакетов

SUSE Linux Enterprise Module for Web and Scripting 12
nodejs4-4.6.0-8.1
nodejs4-devel-4.6.0-8.1
nodejs4-docs-4.6.0-8.1
npm4-4.6.0-8.1

Описание

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки

Описание

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.


Затронутые продукты
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.6.0-8.1
SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.6.0-8.1

Ссылки
Уязвимость SUSE-SU-2016:2470-1