PT-2013-5022 · Node.Js+1 · Node.Js+1

Marek Majkowski

·

Published

2013-10-21

·

Updated

2018-08-13

·

CVE-2013-4450

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Node.js versions 0.8.x through 0.8.25 Node.js versions 0.10.x through 0.10.20
Description The issue allows remote attackers to cause a denial of service by sending a large number of pipelined requests without reading the response, leading to memory and CPU consumption.
Recommendations For Node.js versions 0.8.x through 0.8.25, update to version 0.8.26 or later. For Node.js versions 0.10.x through 0.10.20, update to version 0.10.21 or later.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1086
CVE-2013-4450
MGASA-2014-0007
RHSA-2013:1842

Affected Products

Alt Linux
Node.Js