Oval Definition:oval:com.ubuntu.xenial:def:20165325000
Revision Date:2016-10-10Version:1
Title:CVE-2016-5325 on Ubuntu 16.04 LTS (xenial) - medium.
Description:CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-5325
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND The 'nodejs' package in xenial was vulnerable but has been fixed (note: '4.2.6~dfsg-1ubuntu4.2').
  • BACK