Bug ID 1095763
Summary VUL-0: CVE-2016-10539: nodejs-negotiator: The header for "Accept-Language" is vulnerable to Regular Expression Denial of Service via a specially crafted string.
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.0
Hardware Other
URL https://smash.suse.de/issue/206878/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2016-10539

negotiator is an HTTP content negotiator for Node.js and is used by many
modules
and frameworks including Express and Koa. The header for "Accept-Language",
when
parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression
Denial of Service via a specially crafted string.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10539
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-10539.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10539
https://nodesecurity.io/advisories/106


You are receiving this mail because: