HTTP: Node dot js Pipelined Requests Denial of Service

This signature detects attempts to exploit a known vulnerability in Node.js. Successful exploitation would result in target system becoming unresponsive.

Extended Description

The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.

Affected Products

Nodejs nodejs

References

CVE: CVE-2013-4450

Short Name
HTTP:NODEJS-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-4450 Denial Node Pipelined Requests Service dot js of
Release Date
10/06/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/80
False Positive
Unknown
Vendors

Nodejs

CVSS Score

5.0

Found a potential security threat?