Lucene search

K
redhatRedHatRHSA-2019:1821
HistoryJul 22, 2019 - 1:09 p.m.

(RHSA-2019:1821) Important: rh-nodejs8-nodejs security update

2019-07-2213:09:06
access.redhat.com
91

0.015 Low

EPSS

Percentile

86.8%

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

The following packages have been upgraded to a later upstream version: rh-nodejs8-nodejs (8.16.0). (BZ#1665986, BZ#1710734)

Security Fix(es):

  • nodejs-tar: Arbitrary file overwrites when extracting tarballs containing a hard-link (CVE-2018-20834)

  • nodejs: HTTP request splitting (CVE-2018-12116)

  • nodejs: Denial of Service with large HTTP headers (CVE-2018-12121)

  • nodejs: Slowloris HTTP Denial of Service (CVE-2018-12122)

  • nodejs: Hostname spoofing in URL parser for javascript protocol (CVE-2018-12123)

  • nodejs: Insufficient Slowloris fix causing DoS via server.headersTimeout bypass (CVE-2019-5737)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.