oss-sec mailing list archives

CVE request: node.js <0.6.17/0.7.8 HTTP server information disclosure


From: Alex Legler <a3li () gentoo org>
Date: Tue, 8 May 2012 10:43:15 +0200

Hi,

I didn't see a CVE/request for this one yet:

http://blog.nodejs.org/2012/05/07/http-server-security-vulnerability-please-
upgrade-to-0-6-17/

"A carefully crafted attack request can cause the contents of the HTTP 
parser’s buffer to be appended to the attacking request’s header, making it 
appear to come from the attacker. Since it is generally safe to echo back 
contents of a request, this can allow an attacker to get an otherwise 
correctly designed server to divulge information about other requests. It is 
theoretically possible that it could enable header-spoofing attacks, though 
such an attack has not been demonstrated."

Fix: https://github.com/joyent/node/commit/c9a231d

Thanks,
Alex

-- 
Alex Legler <a3li () gentoo org>
Gentoo Security/Ruby/Infrastructure

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: