Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2330
Description:The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
Test IDs: 1.3.6.1.4.1.25623.1.0.71382  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2330
49066
http://secunia.com/advisories/49066
[oss-security] 20120508 CVE request: node.js <0.6.17/0.7.8 HTTP server information disclosure
http://www.openwall.com/lists/oss-security/2012/05/08/4
[oss-security] 20120508 Re: CVE request: node.js <0.6.17/0.7.8 HTTP server information disclosure
http://www.openwall.com/lists/oss-security/2012/05/08/8
http://blog.nodejs.org/2012/05/04/version-0-6-17-stable/
http://blog.nodejs.org/2012/05/04/version-0-6-17-stable/
https://github.com/joyent/node/commit/7b3fb22
https://github.com/joyent/node/commit/7b3fb22
https://github.com/joyent/node/commit/c9a231d
https://github.com/joyent/node/commit/c9a231d
https://support.f5.com/csp/article/K99038439?utm_source=f5support&%3Butm_medium=RSS
https://support.f5.com/csp/article/K99038439?utm_source=f5support&%3Butm_medium=RSS




© 1998-2025 E-Soft Inc. All rights reserved.