Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1591006 - (CVE-2018-7167) CVE-2018-7167 nodejs: Denial of Service by calling Buffer.fill() or Buffer.alloc() with specially crafted parameters
CVE-2018-7167 nodejs: Denial of Service by calling Buffer.fill() or Buffer.al...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180612,repor...
: Security
Depends On: 1591007 1596637 1596638 1591008 1591009
Blocks: 1591010
  Show dependency treegraph
 
Reported: 2018-06-13 18:05 EDT by Laura Pardo
Modified: 2018-10-03 09:22 EDT (History)
41 users (show)

See Also:
Fixed In Version: nodejs 10.4.1, nodejs 9.11.2, nodejs 8.11.3, nodejs 6.14.3
Doc Type: If docs needed, set a value
Doc Text:
It was found that the Buffer.fill() and Buffer.alloc() function may hang. An attacker able to control the input of these function could use this flaw to cause a denial of service.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Laura Pardo 2018-06-13 18:05:52 EDT
A flaw was found in Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x. Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service.


References:
https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/
Comment 1 Laura Pardo 2018-06-13 18:06:53 EDT
Created nodejs tracking bugs for this issue:

Affects: epel-all [bug 1591007]
Affects: fedora-all [bug 1591009]
Comment 4 Cedric Buissart 2018-06-28 09:45:05 EDT
Upstream fix:
https://github.com/nodejs/node/commit/7dbcfc6217
Comment 6 Jason Shepherd 2018-06-29 01:43:05 EDT
RHOAR NodeJS 10.4.1, has already been released with fixes for this issue.
Comment 12 Jason Shepherd 2018-08-07 00:43:19 EDT
While jenkins-slave-nodejs8 includes a vulnerable version of NodeJS 8, users are not able to affect other uses of the platform.
Comment 14 Jason Shepherd 2018-09-03 23:46:59 EDT
NodeJS 0.10 used by openshift-enterprise-3/logging-auth-proxy is not affected by this issue.
Comment 15 Jason Shepherd 2018-09-03 23:52:11 EDT
openshift-enterprise-3/logging-kibana doesn't make use of the code affected by this flaw

Note You need to log in before you can comment on or make changes to this bug.