Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian: DSA-2021-1234-01 Important: XSecure Module Exploit

red hat
Calendar Grey October 18, 2017
Scroller Redhat
Intermediate security note regarding the rh-nodejs4-nodejs-tough-cookie patch targeting Denial of Service vulnerabilities within Red Hat Software Collections.
An update for rh-nodejs4-nodejs-tough-cookie is now available for Red Hat Software Collections

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Tough-Cookie is a Node.js module that offers RFC6265 Cookies and Cookie Jar.
The following packages have been upgraded to a later upstream version: rh-nodejs4-nodejs-tough-cookie (2.3.3). (BZ#1497695)
Security Fix(es):
* Regular expression denial of service flaws were found in Tough-Cookie. An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU. (CVE-2016-1000232, CVE-2017-15010)

References

https://access.redhat.com/security/cve/CVE-2016-1000232 https://access.redhat.com/security/cve/CVE-2017-15010 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.src.rpm
noarch: rh-nodejs4-nodejs-tough-cookie-2.3.3-2.el7.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:2912-01
Product: Red Hat Software Collections
Issue date: 2017-10-18

Topic

An update for rh-nodejs4-nodejs-tough-cookie is now available for Red HatSoftware Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch

Bugs Fixed

1359818 - CVE-2016-1000232 nodejs-tough-cookie: regular expression DoS via Cookie header with many semicolons

1493989 - CVE-2017-15010 nodejs-tough-cookie: Regular expression denial of service

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.