Bugzilla – Bug 956901
VUL-0: CVE-2015-8027 nodejs: unspecified denial of service vulnerability
Last modified: 2016-01-15 18:14:39 UTC
rh#1285771 A denial of service flaw was reported in Node.js: A bug exists in Node.js, all versions of v0.12.x through to v5.x inclusive, whereby an external attacker can cause a denial of service. Full details of this vulnerability are embargoed until new releases are available on Wednesday the 2nd of December 2015, UTC (Tuesday the 1st of December US time). The versions reported as vulnerable (0.12.x to 5.x) are not shipped in any Red Hat product. This bug will be updated with further information when more details are available. External References: https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/ References: https://bugzilla.redhat.com/show_bug.cgi?id=1285771 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8027 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8027.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8027
bugbot adjusting priority
Releasing update, closing.
openSUSE-SU-2016:0138-1: An update that solves two vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 948045,956901,956902,961254 CVE References: CVE-2015-6764,CVE-2015-8027 Sources used: openSUSE Leap 42.1 (src): nodejs-4.2.4-15.1 openSUSE 13.2 (src): nodejs-4.2.4-9.1 openSUSE 13.1 (src): nodejs-4.2.4-9.1