Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-5325
Description:CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-5325
BugTraq ID: 93483
http://www.securityfocus.com/bid/93483
https://security.gentoo.org/glsa/201612-43
RedHat Security Advisories: RHSA-2016:2101
https://access.redhat.com/errata/RHSA-2016:2101
RedHat Security Advisories: RHSA-2017:0002
http://rhn.redhat.com/errata/RHSA-2017-0002.html
SuSE Security Announcement: SUSE-SU-2016:2470 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html




© 1998-2025 E-Soft Inc. All rights reserved.