PT-2016-6364 · Node.Js+2 · Node.Js+2

Evan Lucas

+1

·

Publicado

2016-10-05

·

Atualizado

2020-01-17

·

CVE-2016-5325

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 0.10.x through 0.10.46 Node.js versions 0.12.x through 0.12.15 Node.js versions 4.x through 4.5.0 Node.js versions 6.x through 6.6.0
Description A CRLF injection issue exists in the ServerResponse#writeHead function, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Recommendations For Node.js versions 0.10.x through 0.10.46, update to version 0.10.47 or later. For Node.js versions 0.12.x through 0.12.15, update to version 0.12.16 or later. For Node.js versions 4.x through 4.5.0, update to version 4.6.0 or later. For Node.js versions 6.x through 6.6.0, update to version 6.7.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2068
CVE-2016-5325
MGASA-2017-0204
OPENSUSE-SU-2016_2496-1
OPENSUSE-SU-2024:10247-1
RHSA-2016:2101
RHSA-2017:0002
SUSE-SU-2016:2470-1
SUSE-SU-2016:2470-2
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1

Produtos afetados

Alt Linux
Node.Js
Suse