Ubuntu Security Update USN-8290-1: Path-to-Regexp vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,770
Reaction score
74
Credits
-1,257
It was discovered that Path-to-Regexp incorrectly handled route patterns containing multiple named parameters separated by non-delimiter characters such as hyphens. An attacker could possibly use this issue to cause a denial of service via catastrophic backtracking in the generated regular expressions.

Continue reading...
 


Follow Linux.org

Staff online


Top