Bug 956901 (CVE-2015-8027) - VUL-0: CVE-2015-8027 nodejs: unspecified denial of service vulnerability
Summary: VUL-0: CVE-2015-8027 nodejs: unspecified denial of service vulnerability
Status: RESOLVED FIXED
Alias: CVE-2015-8027
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Joachim Gleissner
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/159140/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-11-27 07:42 UTC by Alexander Bergmann
Modified: 2016-01-15 18:14 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2015-11-27 07:42:52 UTC
rh#1285771

A denial of service flaw was reported in Node.js:

A bug exists in Node.js, all versions of v0.12.x through to v5.x inclusive, whereby an external attacker can cause a denial of service.

Full details of this vulnerability are embargoed until new releases are available on Wednesday the 2nd of December 2015, UTC (Tuesday the 1st of December US time).

The versions reported as vulnerable (0.12.x to 5.x) are not shipped in any Red Hat product. This bug will be updated with further information when more details are available.

External References:

https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1285771
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8027
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8027.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8027
Comment 1 Swamp Workflow Management 2015-11-27 23:00:14 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-01-15 14:43:12 UTC
Releasing update, closing.
Comment 3 Swamp Workflow Management 2016-01-15 18:14:39 UTC
openSUSE-SU-2016:0138-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 948045,956901,956902,961254
CVE References: CVE-2015-6764,CVE-2015-8027
Sources used:
openSUSE Leap 42.1 (src):    nodejs-4.2.4-15.1
openSUSE 13.2 (src):    nodejs-4.2.4-9.1
openSUSE 13.1 (src):    nodejs-4.2.4-9.1