Vulnerability Bulletins

IBM Security Bulletin: Security Bulletin: Vulnerabilities in OpenSSL and ReDoS vulnerability in semver module affect IBM® SDK for Node.js™ in IBM Bluemix (CVE-2016-2107, CVE-2016-2105, CVE-2

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs. The “semver” module is vulnerable to regular expression denial of service (ReDoS) when extremely long version strings are parsed.CVE(s): CVE-2016-2107, CVE-2016-2105, CVE-2015-8855Affected product(s) and affected version(s):CVE-2016-2107 affects IBM SDK for Node.js v1.1.1.0 and earlier releases. All listed

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-security-bulletin-vulnerabilities-in-openssl-and-redos-vulnerability-in-semver-module-affect-ibm-sdk-for-node-js-in-ibm-bluemix-cve-2016-2107-cve-2016-2105-cv/