CVE Vulnerabilities

CVE-2016-7099

Published: Oct 10, 2016 | Modified: Jan 05, 2018
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
7.4 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Node.js Nodejs 0.10.0 (including) 0.10.0 (including)
Node.js Nodejs 0.10.1 (including) 0.10.1 (including)
Node.js Nodejs 0.10.2 (including) 0.10.2 (including)
Node.js Nodejs 0.10.3 (including) 0.10.3 (including)
Node.js Nodejs 0.10.4 (including) 0.10.4 (including)
Node.js Nodejs 0.10.5 (including) 0.10.5 (including)
Node.js Nodejs 0.10.6 (including) 0.10.6 (including)
Node.js Nodejs 0.10.7 (including) 0.10.7 (including)
Node.js Nodejs 0.10.8 (including) 0.10.8 (including)
Node.js Nodejs 0.10.9 (including) 0.10.9 (including)
Node.js Nodejs 0.10.10 (including) 0.10.10 (including)
Node.js Nodejs 0.10.11 (including) 0.10.11 (including)
Node.js Nodejs 0.10.12 (including) 0.10.12 (including)
Node.js Nodejs 0.10.13 (including) 0.10.13 (including)
Node.js Nodejs 0.10.14 (including) 0.10.14 (including)
Node.js Nodejs 0.10.15 (including) 0.10.15 (including)
Node.js Nodejs 0.10.16 (including) 0.10.16 (including)
Node.js Nodejs 0.10.16-isaacs-manual (including) 0.10.16-isaacs-manual (including)
Node.js Nodejs 0.10.17 (including) 0.10.17 (including)
Node.js Nodejs 0.10.18 (including) 0.10.18 (including)
Node.js Nodejs 0.10.19 (including) 0.10.19 (including)
Node.js Nodejs 0.10.20 (including) 0.10.20 (including)
Node.js Nodejs 0.10.21 (including) 0.10.21 (including)
Node.js Nodejs 0.10.22 (including) 0.10.22 (including)
Node.js Nodejs 0.10.23 (including) 0.10.23 (including)
Node.js Nodejs 0.10.24 (including) 0.10.24 (including)
Node.js Nodejs 0.10.25 (including) 0.10.25 (including)
Node.js Nodejs 0.10.26 (including) 0.10.26 (including)
Node.js Nodejs 0.10.27 (including) 0.10.27 (including)
Node.js Nodejs 0.10.28 (including) 0.10.28 (including)
Node.js Nodejs 0.10.29 (including) 0.10.29 (including)
Node.js Nodejs 0.10.30 (including) 0.10.30 (including)
Node.js Nodejs 0.10.31 (including) 0.10.31 (including)
Node.js Nodejs 0.10.32 (including) 0.10.32 (including)
Node.js Nodejs 0.10.33 (including) 0.10.33 (including)
Node.js Nodejs 0.10.34 (including) 0.10.34 (including)
Node.js Nodejs 0.10.35 (including) 0.10.35 (including)
Node.js Nodejs 0.10.36 (including) 0.10.36 (including)
Node.js Nodejs 0.10.37 (including) 0.10.37 (including)
Node.js Nodejs 0.10.38 (including) 0.10.38 (including)
Node.js Nodejs 0.10.39 (including) 0.10.39 (including)
Node.js Nodejs 0.10.40 (including) 0.10.40 (including)
Node.js Nodejs 0.10.41 (including) 0.10.41 (including)
Node.js Nodejs 0.10.42 (including) 0.10.42 (including)
Node.js Nodejs 0.10.43 (including) 0.10.43 (including)
Node.js Nodejs 0.10.44 (including) 0.10.44 (including)
Node.js Nodejs 0.10.45 (including) 0.10.45 (including)
Node.js Nodejs 0.10.46 (including) 0.10.46 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-nodejs4-http-parser-0:2.7.0-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-nodejs4-nodejs-0:4.6.2-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-nodejs4-http-parser-0:2.7.0-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-nodejs4-nodejs-0:4.6.2-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs4-http-parser-0:2.7.0-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs4-nodejs-0:4.6.2-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-nodejs4-http-parser-0:2.7.0-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-nodejs4-nodejs-0:4.6.2-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-nodejs4-http-parser-0:2.7.0-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-nodejs4-nodejs-0:4.6.2-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat rh-nodejs4-http-parser-0:2.7.0-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat rh-nodejs4-nodejs-0:4.6.2-4.el7 *
Nodejs Ubuntu artful *
Nodejs Ubuntu esm-apps/xenial *
Nodejs Ubuntu precise *
Nodejs Ubuntu trusty *
Nodejs Ubuntu trusty/esm *
Nodejs Ubuntu upstream *
Nodejs Ubuntu xenial *
Nodejs Ubuntu yakkety *
Nodejs Ubuntu zesty *

References