ELSA-2019-3497

ELSA-2019-3497 - http-parser security and bug fix update

Type:SECURITY
Impact:MODERATE
Release Date:2019-11-14

Description


[2.8.0-5]
- Resolves: rhbz#1686488: 'make test' fails with stringop-overflow error

[2.8.0-4]
- Resolves: rhbz#1666382: CVE-2018-12121 http-parser: nodejs: Denial of
Service with large HTTP headers [rhel-8]

[2.8.0-3]
- spec: make the check phase conditional


Related CVEs


CVE-2018-12121

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) http-parser-2.8.0-5.el8.src.rpm09fe728bfd4cdd73a4e6fbce9d96a0e46952ca4b36542c8e08bc47037019698b-ol8_aarch64_appstream
http-parser-2.8.0-5.el8.aarch64.rpm922d3b9e0a698a57d3ab24be1ababe5011bb9acaa6416df332bd06abd132273d-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) http-parser-2.8.0-5.el8.src.rpm09fe728bfd4cdd73a4e6fbce9d96a0e46952ca4b36542c8e08bc47037019698b-ol8_x86_64_appstream
http-parser-2.8.0-5.el8.i686.rpmc10fe67a3ccc56eeff85c8335bdc9534db9e27ec5661281da92eebc06cccfa41-ol8_x86_64_appstream
http-parser-2.8.0-5.el8.x86_64.rpm70b5f5581c11b6043ffc05434f97f766772dabb78c2553a1969703d400afe647-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete