Oval Definition:oval:com.ubuntu.disco:def:201640550000000
Revision Date:2017-01-23Version:1
Title:CVE-2016-4055 on Ubuntu 19.04 (disco) - medium.
Description:The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." It was discovered that moment mishandled certain regular expressions. An attacker could use this vulnerability to cause a denial of service.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-4055
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND node-moment package in disco, is related to the CVE in some way and has been fixed (note: '2.20.1+ds-1').
  • BACK