Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8855

Опубликовано: 23 янв. 2017
Источник: debian
EPSS Низкий

Описание

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-semverfixed5.3.0-1package

Примечания

  • https://nodesecurity.io/advisories/semver_redos

  • https://github.com/npm/npm/releases/tag/v2.7.5

  • libv8 is not covered by security support

EPSS

Процентиль: 76%
0.01023
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

redhat
около 10 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
nvd
больше 8 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
github
больше 7 лет назад

Regular Expression Denial of Service in semver

EPSS

Процентиль: 76%
0.01023
Низкий