CVE-2012-2330
published 2012-08-13CVE-2012-2330: The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote…
PriorityP428medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.60%
83.7th percentile
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 0.6.17~dfsg1-1 (bookworm) | nodejs 0.6.17~dfsg1-1 (bookworm) |
| nodejs | nodejs | <= 0.6.16 | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | >= 0 < 0.6.17~dfsg1-1 | 0.6.17~dfsg1-1 |
| nodejs | nodejs | >= 0 < 0.6.17~dfsg1-1 | 0.6.17~dfsg1-1 |
| nodejs | nodejs | >= 0 < 0.6.17~dfsg1-1 | 0.6.17~dfsg1-1 |
| nodejs | nodejs | >= 0 < 0.6.17~dfsg1-1 | 0.6.17~dfsg1-1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5j8w-g8hc-6222: The Update method in src/node_http_parser
ghsa_unreviewed·2022-05-13
CVE-2012-2330 [MEDIUM] CWE-20 GHSA-5j8w-g8hc-6222: The Update method in src/node_http_parser
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
OSV
CVE-2012-2330: The Update method in src/node_http_parser
osv·2012-08-13·CVSS 6.4
CVE-2012-2330 [MEDIUM] CVE-2012-2330: The Update method in src/node_http_parser
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
Debian
CVE-2012-2330: nodejs - The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 be...
vendor_debian·2012·CVSS 6.4
CVE-2012-2330 [MEDIUM] CVE-2012-2330: nodejs - The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 be...
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
Scope: local
bookworm: resolved (fixed in 0.6.17~dfsg1-1)
bullseye: resolved (fixed in 0.6.17~dfsg1-1)
forky: resolved (fixed in 0.6.17~dfsg1-1)
sid: resolved (fixed in 0.6.17~dfsg1-1)
trixie: resolved (fixed in 0.6.17~dfsg1-1)
No detection rules found.
No public exploits indexed.
http://blog.nodejs.org/2012/05/04/version-0-6-17-stable/http://secunia.com/advisories/49066http://www.openwall.com/lists/oss-security/2012/05/08/4http://www.openwall.com/lists/oss-security/2012/05/08/8https://github.com/joyent/node/commit/7b3fb22https://github.com/joyent/node/commit/c9a231dhttps://support.f5.com/csp/article/K99038439?utm_source=f5support&%3Butm_medium=RSShttp://blog.nodejs.org/2012/05/04/version-0-6-17-stable/http://secunia.com/advisories/49066http://www.openwall.com/lists/oss-security/2012/05/08/4http://www.openwall.com/lists/oss-security/2012/05/08/8https://github.com/joyent/node/commit/7b3fb22https://github.com/joyent/node/commit/c9a231dhttps://support.f5.com/csp/article/K99038439?utm_source=f5support&%3Butm_medium=RSS
2012-08-13
Published