Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1285771 - (CVE-2015-8027) CVE-2015-8027 nodejs: unspecified denial of service vulnerability
CVE-2015-8027 nodejs: unspecified denial of service vulnerability
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20151125,repor...
: Security
Depends On:
Blocks: 1285777
  Show dependency treegraph
 
Reported: 2015-11-26 07:29 EST by Martin Prpič
Modified: 2016-04-27 01:30 EDT (History)
36 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-12-22 17:04:05 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 2105161 None None None 2015-12-22 10:22 EST

  None (edit)
Description Martin Prpič 2015-11-26 07:29:19 EST
A denial of service flaw was reported in Node.js:

A bug exists in Node.js, all versions of v0.12.x through to v5.x inclusive, whereby an external attacker can cause a denial of service.

Full details of this vulnerability are embargoed until new releases are available on Wednesday the 2nd of December 2015, UTC (Tuesday the 1st of December US time).

The versions reported as vulnerable (0.12.x to 5.x) are not shipped in any Red Hat product. This bug will be updated with further information when more details are available.

External References:

https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/
Comment 3 Kurt Seifried 2015-12-22 17:03:00 EST
Statement:

This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Software Collections version 2, Red Hat OpenStack Platform and Red Hat Openshift Enterprise and Openshift Online as they do not include the vulnerable version of nodejs.

Note You need to log in before you can comment on or make changes to this bug.