[Bug 988710] New: VUL-0: CVE-2016-1000022: nodejs-negotiator: Regular expression denial-of-service
http://bugzilla.opensuse.org/show_bug.cgi?id=988710 Bug ID: 988710 Summary: VUL-0: CVE-2016-1000022: nodejs-negotiator: Regular expression denial-of-service Classification: openSUSE Product: openSUSE.org Version: unspecified Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: 3rd party software Assignee: i@marguerite.su Reporter: astieger@suse.com QA Contact: opensuse-communityscreening@forge.provo.novell.com CC: joachim.gleissner@suse.com Found By: Security Response Team Blocker: --- Courtesy bug from the SUSE security bug against devel:languages:nodejs/nodejs-negotiator
The header for "Accept-Language", when parsed by negotiator is vulnerable to Regular Expression Denial of Service via a specially crafted string. devel:languages:nodejs/nodejs-negotiator is at 0.5.3, Fix is in 0.6.1 References: https://bugzilla.redhat.com/show_bug.cgi?id=1347677 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=988710 http://bugzilla.opensuse.org/show_bug.cgi?id=988710#c2 Marguerite Su <i@marguerite.su> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|i@marguerite.su |amajer@suse.com --- Comment #2 from Marguerite Su <i@marguerite.su> --- reassigned to Adam. Now I'm busy reworking the nodejs-packaging codes so Adam please help with this (I think it's been disabled and it's not a Factory package...nothing we can do here). -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=988710 http://bugzilla.opensuse.org/show_bug.cgi?id=988710#c3 Karl Cheng <qantas94heavy@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |qantas94heavy@gmail.com Resolution|--- |FIXED --- Comment #3 from Karl Cheng <qantas94heavy@gmail.com> --- Updated to 0.6.1 by sr#613943. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com