Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs"
},
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs-dbg"
},
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs-dbgsym"
},
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs-dev"
},
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs-dev-dbgsym"
},
{
"binary_version": "4.2.6~dfsg-1ubuntu4.1",
"binary_name": "nodejs-legacy"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "8.10.0~dfsg-2",
"binary_name": "nodejs"
},
{
"binary_version": "8.10.0~dfsg-2",
"binary_name": "nodejs-dbgsym"
},
{
"binary_version": "8.10.0~dfsg-2",
"binary_name": "nodejs-dev"
},
{
"binary_version": "8.10.0~dfsg-2",
"binary_name": "nodejs-doc"
}
]
}