FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

node -- access to unintended files

Affected packages
8.5.0 <= node < 8.6.0

Details

VuXML ID 1257718e-be97-458a-9744-d938b592db42
Discovery 2017-09-27
Entry 2017-10-10

node developers report:

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

References

CVE Name CVE-2017-14849
URL http://www.securityfocus.com/bid/101056