Oval Definition:oval:com.ubuntu.disco:def:201670990000000
Revision Date:2016-10-10Version:1
Title:CVE-2016-7099 on Ubuntu 19.04 (disco) - medium.
Description:The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. Alexander Minozhenko and James Bunton discovered that Node.js did not properly handle wildcards in name fields of X.509 TLS certificates. An attacker could use this vulnerability to execute a man-in-the-middle-attack.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-7099
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND nodejs package in disco, is related to the CVE in some way and has been fixed (note: '8.11.2~dfsg-1').
  • BACK