Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1146063 - (CVE-2014-6394) CVE-2014-6394 nodejs-send: directory traversal vulnerability
CVE-2014-6394 nodejs-send: directory traversal vulnerability
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20140912,reported=2...
: Security
Depends On: 1146064 1146065
Blocks: 1146067
  Show dependency treegraph
 
Reported: 2014-09-24 07:39 EDT by Vasyl Kaigorodov
Modified: 2015-07-31 03:27 EDT (History)
15 users (show)

See Also:
Fixed In Version: nodejs-send 0.8.4
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-10-30 01:31:56 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vasyl Kaigorodov 2014-09-24 07:39:25 EDT
When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory. For example, static(_dirname + '/public') would allow access to _dirname + '/public-restricted'.

Upstream commit: https://github.com/visionmedia/send/commit/9c6ca9b2c0b880afd3ff91ce0d211213c5fa5f9a
Corresponding pull request: https://github.com/visionmedia/send/pull/59
CVE request: http://seclists.org/oss-sec/2014/q3/640
Comment 1 Vasyl Kaigorodov 2014-09-24 07:40:06 EDT
Created nodejs-send tracking bugs for this issue:

Affects: fedora-all [bug 1146064]
Affects: epel-all [bug 1146065]
Comment 2 Fedora Update System 2014-09-29 00:03:44 EDT
nodejs-send-0.3.0-4.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 3 Fedora Update System 2014-10-06 01:00:32 EDT
nodejs-send-0.3.0-4.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2014-10-06 01:06:06 EDT
nodejs-send-0.3.0-4.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.