Node.js qs Module Denial of Service Vulnerability
BID:70113
Info
Node.js qs Module Denial of Service Vulnerability
| Bugtraq ID: | 70113 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-7191 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2014 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Dustin Shiver |
| Vulnerable: |
qs qs 0 IBM SDK for Node.js 1.1.0.7 IBM SDK for Node.js 1.1.0.6 IBM SDK for Node.js 1.1.0.5 IBM SDK for Node.js 1.1.0.3 IBM SDK for Node.js 1.1.0.2 IBM SDK for Node.js 1.1 IBM Rational Software Architect RealTime Edition 9.1.1 IBM Rational Software Architect RealTime Edition 9.1 IBM Rational Software Architect 9.1.1 IBM Rational Software Architect 9.1 IBM Rational Application Developer for WebSphere 9.1.1 IBM Rational Application Developer for WebSphere 9.1.0.1 IBM Rational Application Developer for WebSphere 9.1 IBM Business Process Manager Standard 8.5.5 IBM Business Process Manager Express 8.5.5 IBM Business Process Manager Advanced 8.5.5 |
| Not Vulnerable: |
qs qs 1.0.0 |
Solution / Fix
Node.js qs Module Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Node.js qs Module Denial of Service Vulnerability
References:
References:
- Node.js Homepage (Joyent)
- qs Denial-of-Service Memory Exhaustion (Dustin Shiver)
- Multiple vulnerabilities affecting the Cordova platform and IBM SDK Node.js pack (IBM)
- qs HomePage (qs)
- Security Bulletin: Current Release of IBM® SDK for Node.js�?� is affected by CVE-2 (IBM)
- Security Bulletin: Multiple vulnerabilities in modules from the IBM SDK for Node (IBM)
- Security Bulletin: Multiple vulnerabilities in modules from the IBM SDK for Node (IBM)
- Security Bulletin:Current Release of IBM SDK Node.js is affected by (CVE-2014-71 (IBM)
- Security vulnerabilities in Node.js modules affect IBM Business Process Manager (IBM)