suse · CVE-2016-7099

Quick triage

Priority: high Published: 2021-05-30 13:45:21 UTC Updated: 2023-12-09 01:13:57 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-7099 severity important: SUSE including 73 source package names (MozillaFirefox-68.2.0-78.51.4, MozillaFirefox-branding-SLED-68-21.9.8, …), 237 product×package rows across 21 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (21 product lines)): Fixed 151, Known Not Affected 86.

Description:

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

cvelogic Threat Intelligence