nodejs (0.10.25~dfsg2-2ubuntu1.2) trusty-security; urgency=medium
* SECURITY UPDATE: CRLF injection vulnerability
- debian/patches/CVE-2016-5325.patch: Previously, the reason argument
passed to ServerResponse#writeHead was not being properly validated. One
could pass CRLFs which could lead to http response splitting. This
commit changes the behavior to throw an error in the event any invalid
characters are included in the reason.
lib/http.js
- CVE-2016-5325
Date: 2018-08-09 21:07:15.655029+00:00
Changed-By: Mike Salvatore <[email protected]>
https://launchpad.net/ubuntu/+source/nodejs/0.10.25~dfsg2-2ubuntu1.2
Sorry, changesfile not available.
--
Trusty-changes mailing list
[email protected]
Modify settings or unsubscribe at:
https://lists.ubuntu.com/mailman/listinfo/trusty-changes