[SECURITY] Fedora 21 Update: nodejs-qs-0.6.6-3.fc21

updates at fedoraproject.org updates at fedoraproject.org
Mon Sep 29 04:02:52 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-11309
2014-09-24 18:09:31
--------------------------------------------------------------------------------

Name        : nodejs-qs
Product     : Fedora 21
Version     : 0.6.6
Release     : 3.fc21
URL         : https://github.com/visionmedia/node-querystring
Summary     : Query string parser for Node.js
Description :
This is a query string parser for node and the browser supporting nesting,
as it was removed from 0.3.x, so this library provides the previous and
commonly desired behavior (and twice as fast). Used by express, connect
and others.

--------------------------------------------------------------------------------
Update Information:

The qs module has the ability to create sparse arrays during parsing. By specifying a high index it is possible to create a large array that will eventually take up all the allocated memory of the running process, resulting in a crash.

More information: https://github.com/visionmedia/node-querystring/issues/104

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1146054 - nodejs-qs: Denial-of-Service Memory Exhaustion
        https://bugzilla.redhat.com/show_bug.cgi?id=1146054
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update nodejs-qs' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list