Red Hat Bugzilla – Bug 1588890
CVE-2017-16030 nodejs-useragent: Regular expression Denial-of-Service via long UserAgent header
Last modified: 2018-06-07 22:36:35 EDT
nodejs-useragent before version 2.1.13 is vulnerable to regular expression denial of service when an arbitrarily long User-Agent header is parsed. Reference: https://nodesecurity.io/advisories/312# Upstream Patches: https://github.com/3rd-Eden/useragent/commit/cbc106584bc417bd5843d3e0fa4d89ef81cd6988 https://github.com/3rd-Eden/useragent/commit/b18cf7c2a13c994ea8d6d0d132feef4eb8193c36