Red Hat Bugzilla – Bug 1285774
CVE-2015-6764 v8: unspecified out-of-bounds access vulnerability
Last modified: 2016-04-26 11:45:44 EDT
An out-of-bounds access vulnerability in Node.js:
Full details of this vulnerability are embargoed until new releases are available on Wednesday the 2nd of December 2015, UTC (Tuesday the 1st of December US time).
The versions reported as vulnerable (4.x and 5.x) are not shipped in any Red Hat product. This bug will be updated with further information when more details are available.
Chrome 47.0.2526.73 has also fixed this issue based on the CVE list in:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:2545 https://rhn.redhat.com/errata/RHSA-2015-2545.html
This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Software Collections version 2, Red Hat OpenStack Platform and Red Hat Openshift Enterprise and Openshift Online as they do not include the vulnerable version of nodejs.