|
|||
Rule General Information |
---|
Release Date: | 2018-03-13 | |
Rule Name: | Node.js zlib windowBits Denial of Service Vulnerability -2 (CVE-2017-14919) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter. | |
Impact: | An attacker can launch a denial of service attack by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:101881 https://nodejs.org/en/blog/release/v4.8.5/ https://nodejs.org/en/blog/release/v6.11.5/ https://nodejs.org/en/blog/release/v8.8.0/ https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ |
|
Solutions |
---|
Upgrade to version 4.8.5, 6.11.5 or 8.8.0 to solve the problem. |