Bug#914941: http-parser: CVE-2018-12121

2019-07-21 Thread Jérémy Lal
Le dim. 21 juil. 2019 à 23:20, Florian Weimer a écrit : > * Jérémy Lal: > > > Le dim. 21 juil. 2019 à 22:08, Florian Weimer a > écrit : > > > >> * Jérémy Lal: > >> > >> > I believe this commit should partly be applied to http-parser: > >> > https://github.com/nodejs/node/commit/a8532d4d2 > >> >

Bug#914941: http-parser: CVE-2018-12121

2019-07-21 Thread Florian Weimer
* Jérémy Lal: > Le dim. 21 juil. 2019 à 22:08, Florian Weimer a écrit : > >> * Jérémy Lal: >> >> > I believe this commit should partly be applied to http-parser: >> > https://github.com/nodejs/node/commit/a8532d4d2 >> > >> > Specifically setting HTTP_MAX_HEADER_SIZE to a more reasonnable >> >

Bug#914941: http-parser: CVE-2018-12121

2019-07-21 Thread Jérémy Lal
Le dim. 21 juil. 2019 à 22:08, Florian Weimer a écrit : > * Jérémy Lal: > > > I believe this commit should partly be applied to http-parser: > > https://github.com/nodejs/node/commit/a8532d4d2 > > > > Specifically setting HTTP_MAX_HEADER_SIZE to a more reasonnable > > default (8192 instead of

Bug#914941: http-parser: CVE-2018-12121

2019-07-21 Thread Florian Weimer
* Jérémy Lal: > I believe this commit should partly be applied to http-parser: > https://github.com/nodejs/node/commit/a8532d4d2 > > Specifically setting HTTP_MAX_HEADER_SIZE to a more reasonnable > default (8192 instead of 81920 bytes) should be good for all other > software depending on

Bug#914941: http-parser: CVE-2018-12121

2018-11-28 Thread Jérémy Lal
Source: http-parser Severity: important Tags: security Hi, I believe this commit should partly be applied to http-parser: https://github.com/nodejs/node/commit/a8532d4d2 Specifically setting HTTP_MAX_HEADER_SIZE to a more reasonnable default (8192 instead of 81920 bytes) should be good for all