Candidate: CVE-2018-12122 PublicDate: 2018-11-28 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12122 https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/ Description: Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time. Ubuntu-Description: Jan Maybach discovered that Nde.js did not time out if incomplete HTTP/HTTPS headers were received. An attacker could use this vulnerability to cause a denial of service by keeping HTTP/HTTPS connections alive for a long period of time. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_nodejs: upstream_nodejs: released (8.14.0, 10.14.0) precise/esm_nodejs: DNE trusty_nodejs: ignored (out of standard support) trusty/esm_nodejs: needed xenial_nodejs: ignored (end of standard support, was needed) bionic_nodejs: needed cosmic_nodejs: ignored (reached end-of-life) disco_nodejs: not-affected (10.15.1~dfsg-5) eoan_nodejs: not-affected (10.15.1~dfsg-5) focal_nodejs: not-affected (10.15.1~dfsg-5) groovy_nodejs: not-affected (10.15.1~dfsg-5) hirsute_nodejs: not-affected (10.15.1~dfsg-5) impish_nodejs: not-affected (10.15.1~dfsg-5) jammy_nodejs: not-affected (10.15.1~dfsg-5) devel_nodejs: not-affected (10.15.1~dfsg-5)