CVE-2015-8027: High severity langgenius dify node.js vulnerability
Published Jan 2, 2016
·Updated
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.
Affected Software
14 affected components
Nodejs Node.js=0.12.0
Nodejs Node.js=0.12.1
Nodejs Node.js=0.12.2
Nodejs Node.js=0.12.3
Nodejs Node.js=0.12.4
Nodejs Node.js=0.12.5
Nodejs Node.js=0.12.6
Nodejs Node.js=0.12.7
Nodejs Node.js=0.12.8
Nodejs Node.js=4.2.0
Nodejs Node.js=4.2.1
Nodejs Node.js=4.2.2
Nodejs Node.js=5.0.0
Nodejs Node.js=5.1.0
Event History
Jan 2, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8027?
CVE-2015-8027 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-8027?
To fix CVE-2015-8027, upgrade Node.js to version 0.12.9 or later, 4.2.3 or later, or 5.1.1 or later.
3
What versions of Node.js are affected by CVE-2015-8027?
Node.js versions 0.12.0 through 0.12.8, 4.0.x before 4.2.3, and 5.0.x before 5.1.1 are affected by CVE-2015-8027.
4
Can CVE-2015-8027 lead to data loss?
CVE-2015-8027 primarily leads to service outage and does not directly cause data loss.
5
Who is impacted by CVE-2015-8027?
Any services using the affected versions of Node.js are at risk of denial of service due to CVE-2015-8027.