Vulnerability Bulletins

IBM Security Bulletin: Current Release of IBM® SDK for Node.js™ in IBM Bluemix is affected by CVE-2015-5380

   
Affected software IBM
 
Denial of service vulnerability caused by an out of bounds write in the V8 JavaScript engines UTF decoder. CVE(s): CVE-2015-5380 Affected product(s) and affected version(s): This vulnerability affects all versions up to and including IBM SDK for Node.js v1.2.0.3 and open-source version v0.12.5 of the Node.js runtime in IBM Bluemix. The issue has been resolved in IBM SDK for Node.js v1.2.0.4 and open-source version v0.12.6 with Node.js Buildpack Version: To check which version of the

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_current_release_of_ibm_sdk_for_node_js_in_ibm_bluemix_is_affected_by_cve_2015_5380?lang=en_us