Bug 1500705 (CVE-2017-16137)
| Summary: | CVE-2017-16137 nodejs-debug: Regular expression Denial of Service | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bdettelb, bleanhar, ccoleman, dblechte, dedgar, dfediuck, dffrench, dmcphers, drusso, eedri, hhorak, jgoulding, jkeck, jmadigan, jorton, jshepherd, kpiwko, kseifried, lgriffin, mgoldboi, michal.skrivanek, ngough, nodejs-sig, omachace, pbraun, pebarbos, piotr1212, pwright, rrajasek, sbonazzo, sgratch, sherold, tchollingsworth, thrcka, tjay, tomckay, trepel, yturgema, zsvetlik |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | nodejs-debug 2.6.9, nodejs-debug 3.1.0 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-02-01 07:48:37 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1500706, 1516739, 1516740 | ||
| Bug Blocks: | 1500709 | ||
|
Description
Andrej Nemec
2017-10-11 11:10:00 UTC
Created nodejs-debug tracking bugs for this issue: Affects: fedora-all [bug 1500706] Created nodejs-debug tracking bugs for this issue: Affects: openshift-1 [bug 1516740] debug formatters.o method not used in RHMAP. Marking as not affected. Statement: This issue affects the versions of rh-nodejs4-nodejs-debug, rh-nodejs6-nodejs-debug, and rh-nodejs8-nodejs-debug as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Red Hat Virtualization 4.2 EUS includes a vulnerable version of nodejs-debug as a part of the ovirt-engine-api-explorer package. This package is removed in Red Hat Virtualization 4.3. Red Hat Quay includes the debug library as a dependency of karma-webpack. It is only used at build time, and not runtime so its impact is reduce to low in Red Hat Quay. This issue has been addressed in the following products: Red Hat Quay 3 Via RHSA-2021:3917 https://access.redhat.com/errata/RHSA-2021:3917 |