VYPR

rpm package

suse/nodejs4&distro=SUSE Enterprise Storage 4

pkg:rpm/suse/nodejs4&distro=SUSE%20Enterprise%20Storage%204

Vulnerabilities (25)

  • CVE-2017-11499HigJul 25, 2017
    affected < 4.8.4-15.5.1fixed 4.8.4-15.5.1

    Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building

  • CVE-2017-1000381HigJul 7, 2017
    affected < 4.8.4-15.5.1fixed 4.8.4-15.5.1

    The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

  • CVE-2016-7055MedMay 4, 2017
    affected < 4.7.3-14.1fixed 4.7.3-14.1

    There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impos

  • CVE-2017-3732MedMay 4, 2017
    affected < 4.7.3-14.1fixed 4.7.3-14.1

    There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and

  • CVE-2017-3731HigMay 4, 2017
    affected < 4.7.3-14.1fixed 4.7.3-14.1

    If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA

Page 2 of 2