[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

nodejs: Slowloris HTTP Denial of Service with keep-alive (CVE-2019-5737)

ID: oval:org.secpod.oval:def:1802060Date: (C)2022-03-25   (M)2024-04-17
Class: PATCHFamily: unix




An attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly thereby keeping the connection and associated resources alive for a long period of time. Attack potential is mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November, 2018. The 40 second timeout and its adjustment by server.headersTimeout apply to this fix as in CVE-2018-12121.

Platform:
Alpine Linux 3.10
Alpine Linux 3.11
Alpine Linux 3.12
Alpine Linux 3.13
Alpine Linux 3.14
Alpine Linux 3.15
Product:
nodejs-current
Reference:
10047
CVE-2019-5737
CVE-2018-12121
CVE    2
CVE-2018-12121
CVE-2019-5737
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.11
cpe:/o:alpinelinux:alpine_linux:3.10

© SecPod Technologies