Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-21270

Опубликовано: 03 дек. 2020
Источник: debian

Описание

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-stringstreamfixed0.0.6-1package

Примечания

  • https://github.com/mhart/StringStream/issues/7

  • https://hackerone.com/reports/321670

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
redhat
около 5 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
nvd
больше 4 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

github
почти 6 лет назад

Out-of-bounds Read in stringstream