Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:2496-1

Опубликовано: 11 окт. 2016
Источник: suse-cvrf

Описание

Security update for nodejs

This update brings the new upstream nodejs LTS version 4.6.0, fixing bugs and security issues:

  • Nodejs embedded openssl version update
    • upgrade to 1.0.2j (CVE-2016-6304, CVE-2016-2183, CVE-2016-2178, CVE-2016-6306, CVE-2016-7052)
    • remove support for dynamic 3rd party engine modules
  • http: Properly validate for allowable characters in input user data. This introduces a new case where throw may occur when configuring HTTP responses, users should already be adopting try/catch here. (CVE-2016-5325, bsc#985201)
  • tls: properly validate wildcard certificates (CVE-2016-7099, bsc#1001652)
  • buffer: Zero-fill excess bytes in new Buffer objects created with Buffer.concat()

Список пакетов

openSUSE Leap 42.1
nodejs-4.6.0-33.1
nodejs-devel-4.6.0-33.1
nodejs-docs-4.6.0-33.1
npm-4.6.0-33.1

Описание

The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки

Описание

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.


Затронутые продукты
openSUSE Leap 42.1:nodejs-4.6.0-33.1
openSUSE Leap 42.1:nodejs-devel-4.6.0-33.1
openSUSE Leap 42.1:nodejs-docs-4.6.0-33.1
openSUSE Leap 42.1:npm-4.6.0-33.1

Ссылки