Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10542

Опубликовано: 31 мая 2018
Источник: debian

Описание

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-wsfixed1.1.0+ds1.e6ddaae4-5package
node-wsfixed1.1.0+ds1.e6ddaae4-3+deb9u1stretchpackage
node-wsend-of-lifejessiepackage

Примечания

  • https://nodesecurity.io/advisories/120

  • https://github.com/nodejs/node/issues/7388

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.

CVSS3: 7.5
nvd
больше 7 лет назад

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.

github
почти 7 лет назад

DoS due to excessively large websocket message in ws