Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia: 2020-0131 Moderate: HTTP-Parser Request Smuggling Issue

mageia
Calendar Grey March 8, 2020
Dist Mageia Esm H88
Mageia enhances its HTTP-parser to tackle transfer-encoding smuggling vulnerabilities affecting various Node.js releases.
http-parser has been updated to fix a security issue

Summary

http-parser has been updated to fix a security issue.
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed (VE-2019-15605).

References

- https://bugs.mageia.org/show_bug.cgi?id=26293

- https://access.redhat.com/errata/RHSA-2020:0703

- https://www.cve.org/CVERecord?id=CVE-2019-15605

Resolution

SRPMS

- 7/core/http-parser-2.9.3-1.mga7

Publication date: 08 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0131.html
Type: security
CVE: CVE-2019-15605

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here