[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:0708-01 -- Redhat http-parser

ID: oval:org.secpod.oval:def:66529Date: (C)2020-10-30   (M)2024-03-14
Class: PATCHFamily: unix




The http-parser package provides a utility for parsing HTTP messages. It parses both requests and responses. The parser is designed to be used in performance HTTP applications. It does not make any system calls or allocations, it does not buffer data, and it can be interrupted at any time. Depending on your architecture, it only requires about 40 bytes of data per message stream. Security Fix: * nodejs: HTTP request smuggling using malformed Transfer-Encoding header For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Platform:
CentOS 8
Product:
http-parser
Reference:
RHSA-2020:0708-01
CVE-2019-15605
CVE    1
CVE-2019-15605
CPE    2
cpe:/o:centos:centos:8
cpe:/a:nodejs:http-parser

© SecPod Technologies