Candidate: CVE-2019-5739 PublicDate: 2019-03-28 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5739 https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/ Description: Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_nodejs: upstream: https://github.com/nodejs/node/commit/e9ae4aaaad upstream_nodejs: released (8.9.3~dfsg-5) precise/esm_nodejs: DNE trusty_nodejs: ignored (out of standard support) trusty/esm_nodejs: not-affected (code not present) xenial_nodejs: ignored (end of standard support, was needed) bionic_nodejs: not-affected (8.10.0~dfsg-2ubuntu0.4) cosmic_nodejs: not-affected disco_nodejs: not-affected eoan_nodejs: not-affected focal_nodejs: not-affected groovy_nodejs: not-affected hirsute_nodejs: not-affected impish_nodejs: not-affected jammy_nodejs: not-affected devel_nodejs: not-affected