Lucene search

K
redhatRedHatRHSA-2016:2101
HistoryOct 27, 2016 - 4:28 p.m.

(RHSA-2016:2101) Moderate: nodejs and nodejs-tough-cookie security, bug fix, and enhancement update

2016-10-2716:28:45
access.redhat.com
35

EPSS

0.006

Percentile

79.2%

Red Hat OpenShift Container Platform is the company’s cloud computing
Platform-as-a-Service (PaaS) solution designed for on-premise or private
cloud deployments.

Security Fix(es):

  • A regular expression denial of service flaw was found in Tough-Cookie. An
    attacker able to make an application using Touch-Cookie to parse a
    sufficiently large HTTP request Cookie header could cause the application
    to consume an excessive amount of CPU. (CVE-2016-1000232)

  • It was found that the reason argument in ServerResponse#writeHead() was
    not properly validated. A remote attacker could possibly use this flaw to
    conduct an HTTP response splitting attack via a specially-crafted HTTP
    request. (CVE-2016-5325)

This advisory contains the RPM packages for this release. See the following
advisory for the container images fixes for this release:

https://access.redhat.com/errata/RHBA-2016:2100