Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2019:0818-1 Moderate: Nodejs6 Denial of Service Fixes

suse
Calendar Grey March 29, 2019
Dist Suse Esm H88
SUSE Security Patch: Urgent update for nodejs6 resolving several vulnerabilities, encompassing Denial of Service threats.
An update that fixes three vulnerabilities is now available

Summary

This update for nodejs6 to version 6.17.0 fixes the following issues: Security issues fixed: - CVE-2019-5739: Fixed a potentially attack vector which could lead to Denial of Service when HTTP connection are kept active (bsc#1127533). - CVE-2019-5737: Fixed a potentially attack vector which could lead to Denial of Service when HTTP connection are kept active (bsc#1127532). - CVE-2019-1559: Fixed OpenSSL 0-byte Record Padding Oracle which under certain circumstances a TLS server can be forced to respond differently to a client and lead to the decryption of the data (bsc#1127080). Release Notes: https://nodejs.org/en/blog/release/v6.17.0/ Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1127080 #1127532 #1127533

Cross- CVE-2019-1559 CVE-2019-5737 CVE-2019-5739

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Module for Web Scripting 12

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2019-1559.html

https://www.suse.com/security/cve/CVE-2019-5737.html

https://www.suse.com/security/cve/CVE-2019-5739.html

https://bugzilla.suse.com/1127080

https://bugzilla.suse.com/1127532

https://bugzilla.suse.com/1127533

Announcement ID: SUSE-SU-2019:0818-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here