Bug 1379921 (CVE-2016-7099)
Summary: | CVE-2016-7099 nodejs: wildcard certificates not properly validated | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Martin Prpič <mprpic> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | abhgupta, ahardin, apevec, avibelli, bleanhar, cbuissar, ccoleman, chrisw, cvsbot-xmlrpc, dbaker, dedgar, dmcphers, gsterlin, hhorak, jbalunas, jgoulding, jialiu, jkeck, joelsmith, jokerman, jorton, jschluet, jshepherd, kbasil, lhh, lmeyer, lpeer, markmc, mchappel, mmccomas, mrunge, nodejs-sig, rbryant, rrajasek, sardella, sclewis, sgallagh, srevivo, tchollingsworth, tdawson, tdecacqu, thrcka, tiwillia, tkirby, zsvetlik |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | nodejs 6.7.0, nodejs 4.6.0, nodejs 0.12.16, nodejs 0.10.47 | Doc Type: | If docs needed, set a value |
Doc Text: |
It was found that Node.js' tls.checkServerIdentity() function did not properly validate server certificates containing wildcards. A malicious TLS server could use this flaw to get a specially crafted certificate accepted by a Node.js TLS client.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 02:59:10 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1379922, 1392912, 1392913, 1392914, 1392915, 1399557, 1417856, 1417957, 1417958, 1470252, 1470253, 1470254, 1470255 | ||
Bug Blocks: | 1346916, 1394602 |
Description
Martin Prpič
2016-09-28 06:35:23 UTC
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 1379922] Upstream commit: 0.10.x https://github.com/nodejs/node/commit/0d7e21ee7bcc79046f898f8c202d2ec87d23d711 4.x https://github.com/nodejs/node/commit/3ff82deb2c3bd580d64be75dbafe460393c952fb Marking nodejs010-nodejs as WONTFIX because nodejs010 is past EOL. For further information regarding Software Collection package life cycle policy, see : https://access.redhat.com/support/policy/updates/rhscl/ This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS Via RHSA-2017:0002 https://rhn.redhat.com/errata/RHSA-2017-0002.html Openshift Enterprise points to rhscl/nodejs-4-rhel7 image which includes node 4.6.2, see: https://github.com/openshift/library/blob/master/official/nodejs/imagestreams/nodejs-rhel7.json Marking Openshift Enterprise as notaffected. |