Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1209496 - (CVE-2015-8855) CVE-2015-8855 nodejs-semver: npm Regular Expression Denial of Service during package versions parsing
CVE-2015-8855 nodejs-semver: npm Regular Expression Denial of Service during ...
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150403,repor...
: Security
Depends On: 1209499 1209498
Blocks: 1209497
  Show dependency treegraph
 
Reported: 2015-04-07 09:39 EDT by Vasyl Kaigorodov
Modified: 2016-04-22 04:00 EDT (History)
6 users (show)

See Also:
Fixed In Version: npm 2.7.5, semver 4.3.2
Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in the way semver, the semantic version comparison library for Node.js, parsed certain package versions. A remote attacker could use a specially crafted version string that, when processed, would lead to excessive CPU consumption.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-04-30 04:58:53 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vasyl Kaigorodov 2015-04-07 09:39:24 EDT
semver is vulnerable to regular expression denial of service (ReDoS) when extremely long version strings are parsed:

https://nodesecurity.io/advisories/semver_redos

Upstream fix:
https://github.com/npm/npm/commit/0dc68757cffd5397c280bc71365d106523a5a052
Comment 1 Vasyl Kaigorodov 2015-04-07 09:41:53 EDT
Created nodejs-semver tracking bugs for this issue:

Affects: fedora-all [bug 1209498]
Affects: epel-all [bug 1209499]
Comment 3 Ján Rusnačko 2015-04-08 04:27:06 EDT
External References:

https://nodesecurity.io/advisories/semver_redos
Comment 5 Andrej Nemec 2016-04-22 04:00:13 EDT
CVE assignment:

http://seclists.org/oss-sec/2016/q2/122

Note You need to log in before you can comment on or make changes to this bug.