Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8277

Опубликовано: 19 нояб. 2020
Источник: debian
EPSS Средний

Описание

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
c-aresfixed1.17.1-1package
c-aresnot-affectedbusterpackage
c-aresnot-affectedstretchpackage

Примечания

  • Originally reported for nodes, which bundles c-ares: https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/#denial-of-service-through-dns-request-cve-2020-8277

  • Fix in c-ares: https://github.com/c-ares/c-ares/commit/0d252eb3b2147179296a3bdb4ef97883c97c54d3

  • Introduced in https://github.com/c-ares/c-ares/commit/7d3591ee8a1a63e7748e68e6d880bd1763a32885

EPSS

Процентиль: 98%
0.59168
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

CVSS3: 7.5
redhat
больше 4 лет назад

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

CVSS3: 7.5
nvd
больше 4 лет назад

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
больше 4 лет назад

Security update for c-ares

EPSS

Процентиль: 98%
0.59168
Средний