Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2016-1000023: nodejs: Regular expression denial-of-service | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Johannes Segitz <jsegitz> |
Component: | Incidents | Assignee: | Jordi Massaguer <jmassaguerpla> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P4 - Low | CC: | qantas94heavy, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/170967/ | ||
Whiteboard: | CVSSv2:RedHat:CVE-2016-1000023:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P) CVSSv2:SUSE:CVE-2016-1000023:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Johannes Segitz
2016-07-21 13:00:30 UTC
bugbot adjusting priority I've asked upstream for an update https://github.com/nodejs/node/issues/7836 answer from upstream (nodejs) "Note that the impact of this in npm bundled with Node.js is negligible — that one is used only for package management, not as a library, and there is entirely no need for a malicious package to even bother with something like ReDOS." So I guess we can just wait for an upstream update given this should have a lower priority, right? (In reply to Jordi Massaguer from comment #3) yes, it's already tagged as VUL-1, so we'll just include it into the next update All current npm packages now have minimatch 3.0.3, which includes the fix for this bug. |