Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16138

Опубликовано: 07 июн. 2018
Источник: debian
EPSS Низкий

Описание

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-mimefixed2.3.1-1package

Примечания

  • https://github.com/broofa/node-mime/issues/167

  • https://nodesecurity.io/advisories/535

  • https://github.com/broofa/node-mime/commit/855d0c4b8b22e4a80b9401a81f2872058eae274d (1.x)

  • https://github.com/broofa/node-mime/commit/1df903fdeb9ae7eaa048795b8d580ce2c98f40b0 (2.x)

  • nodejs not covered by security support

EPSS

Процентиль: 62%
0.00433
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

CVSS3: 5.3
redhat
больше 8 лет назад

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

CVSS3: 7.5
nvd
больше 7 лет назад

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

CVSS3: 7.5
github
больше 7 лет назад

mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input

EPSS

Процентиль: 62%
0.00433
Низкий