Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1591872 - (CVE-2017-16014) CVE-2017-16014 nodejs-http-proxy: DOS via improper error handling in middleware implementation
CVE-2017-16014 nodejs-http-proxy: DOS via improper error handling in middlewa...
Status: CLOSED NEXTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170411,repor...
: Security
Depends On: 1591874
Blocks: 1591875
  Show dependency treegraph
 
Reported: 2018-06-15 13:47 EDT by Pedro Sampaio
Modified: 2018-07-01 23:03 EDT (History)
10 users (show)

See Also:
Fixed In Version: nodejs-http-proxy 0.7.0
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-06-24 05:24:21 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Pedro Sampaio 2018-06-15 13:47:29 EDT
Affected versions of http-proxy are vulnerable to a denial of service attack, wherein an attacker can force an error which will cause the server to crash.

Upstream issue:

https://github.com/nodejitsu/node-http-proxy/pull/101

External references:

https://nodesecurity.io/advisories/323
Comment 1 Pedro Sampaio 2018-06-15 13:48:12 EDT
Created nodejs-http-proxy tracking bugs for this issue:

Affects: fedora-all [bug 1591874]
Comment 2 Parag Nemade 2018-06-16 05:19:53 EDT
May I know why you think given https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already present in Fedora?

The current Fedora release for this package is nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release 1.16.2 which got released in December 2016.

The patch you given in description is already merged in upstream since long time.
Comment 3 Andrej Nemec 2018-06-21 08:12:34 EDT
(In reply to Parag Nemade from comment #2)
> May I know why you think given
> https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already
> present in Fedora?
> 
> The current Fedora release for this package is
> nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release
> 1.16.2 which got released in December 2016.
> 
> The patch you given in description is already merged in upstream since long
> time.

Hi,

This definitely looks like an error, I'll change the status to notaffected and close the associated tracking bug. Thanks for the info!

Note You need to log in before you can comment on or make changes to this bug.