CVE-2013-4450
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and… (CVE-2013-4450)
noneEPSS 37%
Description
Metrics
Severity
none
59.05
no public PoC known
98.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2013-10-21 17:00 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
nodejs
nodejs
References & sources
- https://kb.juniper.net/JSA10783x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2013-1842.htmlvendor-advisoryx_refsource_REDHAT
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00051.htmlvendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2013/10/20/1mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/63229vdb-entryx_refsource_BID
- http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/x_refsource_CONFIRM
- http://blog.nodejs.org/2013/10/18/node-v0-8-26-maintenance/x_refsource_CONFIRM
- https://github.com/rapid7/metasploit-framework/pull/2548x_refsource_MISC
- https://groups.google.com/forum/#%21topic/nodejs/NEbweYB0ei0x_refsource_MISC
- https://github.com/joyent/node/issues/6214x_refsource_CONFIRM
IDCVE-2013-4450