Lucene search

K
cveRedhatCVE-2012-2330
HistoryAug 13, 2012 - 11:55 p.m.

CVE-2012-2330

2012-08-1323:55:01
CWE-20
redhat
web.nvd.nist.gov
36
cve
update method
node.js
security vulnerability
http headers
nvd
remote attackers
sensitive information
spoofing

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.007

Percentile

80.9%

The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.

Affected configurations

Nvd
Node
nodejsnodejsRange0.6.16
OR
nodejsnodejsMatch0.7.0
OR
nodejsnodejsMatch0.7.1
OR
nodejsnodejsMatch0.7.2
OR
nodejsnodejsMatch0.7.3
OR
nodejsnodejsMatch0.7.4
OR
nodejsnodejsMatch0.7.5
OR
nodejsnodejsMatch0.7.6
OR
nodejsnodejsMatch0.7.7
VendorProductVersionCPE
nodejsnodejs*cpe:2.3:a:nodejs:nodejs:*:*:*:*:*:*:*:*
nodejsnodejs0.7.0cpe:2.3:a:nodejs:nodejs:0.7.0:*:*:*:*:*:*:*
nodejsnodejs0.7.1cpe:2.3:a:nodejs:nodejs:0.7.1:*:*:*:*:*:*:*
nodejsnodejs0.7.2cpe:2.3:a:nodejs:nodejs:0.7.2:*:*:*:*:*:*:*
nodejsnodejs0.7.3cpe:2.3:a:nodejs:nodejs:0.7.3:*:*:*:*:*:*:*
nodejsnodejs0.7.4cpe:2.3:a:nodejs:nodejs:0.7.4:*:*:*:*:*:*:*
nodejsnodejs0.7.5cpe:2.3:a:nodejs:nodejs:0.7.5:*:*:*:*:*:*:*
nodejsnodejs0.7.6cpe:2.3:a:nodejs:nodejs:0.7.6:*:*:*:*:*:*:*
nodejsnodejs0.7.7cpe:2.3:a:nodejs:nodejs:0.7.7:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.007

Percentile

80.9%