MGASA-2020-0131 - Updated http-parser packages fix security vulnerability

Publication date: 08 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0131.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-15605

http-parser has been updated to fix a security issue.

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload
delivery when transfer-encoding is malformed (VE-2019-15605).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26293
- https://access.redhat.com/errata/RHSA-2020:0703
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15605

SRPMS:
- 7/core/http-parser-2.9.3-1.mga7

Mageia 2020-0131: http-parser security update

http-parser has been updated to fix a security issue

Summary

http-parser has been updated to fix a security issue.
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed (VE-2019-15605).

References

- https://bugs.mageia.org/show_bug.cgi?id=26293

- https://access.redhat.com/errata/RHSA-2020:0703

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15605

Resolution

MGASA-2020-0131 - Updated http-parser packages fix security vulnerability

SRPMS

- 7/core/http-parser-2.9.3-1.mga7

Severity
Publication date: 08 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0131.html
Type: security
CVE: CVE-2019-15605

Related News