Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-7099
Description:The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.809965   1.3.6.1.4.1.25623.1.0.871993  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-7099
BugTraq ID: 93191
http://www.securityfocus.com/bid/93191
RedHat Security Advisories: RHSA-2017:0002
http://rhn.redhat.com/errata/RHSA-2017-0002.html
SuSE Security Announcement: SUSE-SU-2016:2470 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html




© 1998-2025 E-Soft Inc. All rights reserved.