ELSA-2020-0708

ELSA-2020-0708 - http-parser security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2020-03-06

Description


[2.8.0-5.2]
- Do not break ABI with CVE-2019-15605 fix

[2.8.0-5.1]
- Resolves: CVE-2019-15605 http-parser: nodejs: HTTP request
smuggling using malformed Transfer-Encoding header


Related CVEs


CVE-2019-15605

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) http-parser-2.8.0-5.el8_1.2.src.rpm0fafcdadb17d7f580846314ce325ed96-
http-parser-2.8.0-5.el8_1.2.aarch64.rpmb855c2a54ba91c9f58ece53cd059cd5c-
Oracle Linux 8 (x86_64) http-parser-2.8.0-5.el8_1.2.src.rpm0fafcdadb17d7f580846314ce325ed96-
http-parser-2.8.0-5.el8_1.2.i686.rpm0398e44da43569e69340a7fa96b2cd66-
http-parser-2.8.0-5.el8_1.2.x86_64.rpm3742c33b51b09520db26b9810242b04e-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete