CVE-2016-1000236
19.11.2019, 17:15
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
Vendor | Product | Version |
---|---|---|
cookie-signature_project | cookie-signature | 𝑥 < 1.0.6 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
node-cookie-signature |
|
References