[ALAS2-2020-1417] Amazon Linux 2 2017.12 - ALAS2-2020-1417: important priority package update for http-parser

Severity Important
Affected Packages 9
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2019-15605:
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
1800364: CVE-2019-15605 nodejs: HTTP request smuggling using malformed Transfer-Encoding header

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/http-parser?arch=x86_64&distro=amazonlinux-2 amazonlinux http-parser < 2.7.1-8.amzn2.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/http-parser?arch=i686&distro=amazonlinux-2 amazonlinux http-parser < 2.7.1-8.amzn2.2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/http-parser?arch=aarch64&distro=amazonlinux-2 amazonlinux http-parser < 2.7.1-8.amzn2.2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/http-parser-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux http-parser-devel < 2.7.1-8.amzn2.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/http-parser-devel?arch=i686&distro=amazonlinux-2 amazonlinux http-parser-devel < 2.7.1-8.amzn2.2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/http-parser-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux http-parser-devel < 2.7.1-8.amzn2.2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/http-parser-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux http-parser-debuginfo < 2.7.1-8.amzn2.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/http-parser-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux http-parser-debuginfo < 2.7.1-8.amzn2.2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/http-parser-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux http-parser-debuginfo < 2.7.1-8.amzn2.2 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...