Bug 1285774 (CVE-2015-6764)

Summary: CVE-2015-6764 v8: unspecified out-of-bounds access vulnerability
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, ccoleman, chrisw, dallan, dmcphers, erjones, gkotton, hhorak, jialiu, joelsmith, jokerman, jorton, jschluet, kseifried, lhh, lmeyer, lpeer, markmc, mmaslano, mmccomas, mrunge, rbryant, sardella, sclewis, sgallagh, tchollingsworth, tdecacqu, thrcka, tpopela, yeylon, zsvetlik
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-12-22 22:04:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1287442, 1287443    
Bug Blocks: 1285777, 1287448    

Description Martin Prpič 2015-11-26 12:33:35 UTC
An out-of-bounds access vulnerability in Node.js:

An additional bug exists in Node.js, all versions of v4.x and v5.x, whereby an attacker may be able to trigger an out-of-bounds access and/or denial of service if user-supplied JavaScript can be executed by an application, but only under circumstances where an attacker may cause user-supplied JavaScript to be executed within a Node.js application.

Full details of this vulnerability are embargoed until new releases are available on Wednesday the 2nd of December 2015, UTC (Tuesday the 1st of December US time).

The versions reported as vulnerable (4.x and 5.x) are not shipped in any Red Hat product. This bug will be updated with further information when more details are available.

External References:

https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/

Comment 1 Martin Prpič 2015-12-02 08:37:36 UTC
Chrome 47.0.2526.73 has also fixed this issue based on the CVE list in:

http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html

Comment 2 errata-xmlrpc 2015-12-03 19:40:29 UTC
This issue has been addressed in the following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2015:2545 https://rhn.redhat.com/errata/RHSA-2015-2545.html

Comment 3 Kurt Seifried 2015-12-22 22:03:11 UTC
Statement:

This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Software Collections version 2, Red Hat OpenStack Platform and Red Hat Openshift Enterprise and Openshift Online as they do not include the vulnerable version of nodejs.