|Category:||Mageia Linux Local Security Checks|
|Title:||Mageia Linux Local Check: mgasa-2016-0080|
|Summary:||Mageia Linux Local Security Checks mgasa-2016-0080|
Mageia Linux Local Security Checks mgasa-2016-0080
A request smuggling vulnerability was found in Node.js that can be exploited under certain unspecified circumstances (CVE-2016-2086). It was reported that HTTP header parsing in Node.js is vulnerable to response splitting attacks. While Node.js has been protecting against response splitting attacks by checking for CRLF characters, it is possible to compose response headers using Unicode characters that decompose to these characters, bypassing the checks previously in place (CVE-2016-2216).
Update the affected packages to the latest available version.
Common Vulnerability Exposure (CVE) ID: CVE-2016-2086|
BugTraq ID: 83282
Common Vulnerability Exposure (CVE) ID: CVE-2016-2216
BugTraq ID: 83141
|Copyright||Copyright (C) 2016 Eero Volotinen|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.