Lucene search

K
redhatRedHatRHSA-2015:1546
HistoryAug 04, 2015 - 12:00 a.m.

(RHSA-2015:1546) Important: node.js security update

2015-08-0400:00:00
access.redhat.com
44

0.975 High

EPSS

Percentile

100.0%

OpenShift Enterprise by Red Hat is the company’s cloud computing
Platform-as-a-Service (PaaS) solution designed for on-premise or private
cloud deployments.

Node.js is a software development platform for building fast and scalable
network applications in the JavaScript programming language.

A flaw was found in the way SSL 3.0 handled padding bytes when decrypting
messages encrypted using block ciphers in cipher block chaining (CBC) mode.
This flaw allows a man-in-the-middle (MITM) attacker to decrypt a selected
byte of a cipher text in as few as 256 tries if they are able to force a
victim application to repeatedly send the same data over newly created SSL
3.0 connections. (CVE-2014-3566)

All OpenShift Enterprise users are advised to upgrade to these updated
packages, which correct this issue.