CVE-2017-16005

NameCVE-2017-16005
DescriptionHttp-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-http-signature (PTS)bullseye1.3.5-1fixed
bookworm, sid, trixie1.3.6-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-http-signaturesource(unstable)(not affected)

Notes

- node-http-signature <not-affected> (Fixed before initial upload to Debian)
https://github.com/joyent/node-http-signature/issues/10
https://nodesecurity.io/advisories/318
nodejs not covered by security support

Search for package or bug name: Reporting problems