Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-11499

Опубликовано: 25 июл. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

РелизСтатусПримечание
artful

not-affected

4.8.4~dfsg-1ubuntu1
bionic

not-affected

4.8.4~dfsg-1ubuntu1
cosmic

not-affected

4.8.4~dfsg-1ubuntu1
devel

not-affected

4.8.4~dfsg-1ubuntu1
disco

not-affected

4.8.4~dfsg-1ubuntu1
eoan

not-affected

4.8.4~dfsg-1ubuntu1
esm-apps/bionic

not-affected

4.8.4~dfsg-1ubuntu1
esm-apps/focal

not-affected

4.8.4~dfsg-1ubuntu1
esm-apps/jammy

not-affected

4.8.4~dfsg-1ubuntu1
esm-apps/noble

not-affected

4.8.4~dfsg-1ubuntu1

Показывать по

EPSS

Процентиль: 73%
0.00778
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
nvd
почти 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
debian
почти 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11. ...

CVSS3: 7.5
github
около 3 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

suse-cvrf
почти 8 лет назад

Security update for nodejs4, nodejs6

EPSS

Процентиль: 73%
0.00778
Низкий

5 Medium

CVSS2

7.5 High

CVSS3