Bug 1591872 (CVE-2017-16014) - CVE-2017-16014 nodejs-http-proxy: DOS via improper error handling in middleware implementation
Summary: CVE-2017-16014 nodejs-http-proxy: DOS via improper error handling in middlewa...
Keywords:
Status: CLOSED NEXTRELEASE
Alias: CVE-2017-16014
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1591874
Blocks: 1591875
TreeView+ depends on / blocked
 
Reported: 2018-06-15 17:47 UTC by Pedro Sampaio
Modified: 2021-02-17 00:07 UTC (History)
10 users (show)

Fixed In Version: nodejs-http-proxy 0.7.0
Clone Of:
Environment:
Last Closed: 2018-06-24 09:24:21 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2018-06-15 17:47:29 UTC
Affected versions of http-proxy are vulnerable to a denial of service attack, wherein an attacker can force an error which will cause the server to crash.

Upstream issue:

https://github.com/nodejitsu/node-http-proxy/pull/101

External references:

https://nodesecurity.io/advisories/323

Comment 1 Pedro Sampaio 2018-06-15 17:48:12 UTC
Created nodejs-http-proxy tracking bugs for this issue:

Affects: fedora-all [bug 1591874]

Comment 2 Parag Nemade 2018-06-16 09:19:53 UTC
May I know why you think given https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already present in Fedora?

The current Fedora release for this package is nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release 1.16.2 which got released in December 2016.

The patch you given in description is already merged in upstream since long time.

Comment 3 Andrej Nemec 2018-06-21 12:12:34 UTC
(In reply to Parag Nemade from comment #2)
> May I know why you think given
> https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already
> present in Fedora?
> 
> The current Fedora release for this package is
> nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release
> 1.16.2 which got released in December 2016.
> 
> The patch you given in description is already merged in upstream since long
> time.

Hi,

This definitely looks like an error, I'll change the status to notaffected and close the associated tracking bug. Thanks for the info!


Note You need to log in before you can comment on or make changes to this bug.