Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmqg-p8f8-3qrw

Опубликовано: 18 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Out-of-bounds Read in fast-string-search

All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.

Пакеты

Наименование

fast-string-search

npm
Затронутые версииВерсия исправления

<= 1.4.3

Отсутствует

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125