Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhxj-85r3-2x55

Опубликовано: 22 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

file-type vulnerable to Infinite Loop via malformed MKV file

An issue was discovered in the file-type package from 13.0.0 until 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack when used on a web server.

Пакеты

Наименование

file-type

npm
Затронутые версииВерсия исправления

>= 13.0.0, < 16.5.4

16.5.4

Наименование

file-type

npm
Затронутые версииВерсия исправления

>= 17.0.0, < 17.1.3

17.1.3

EPSS

Процентиль: 31%
0.00119
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.

CVSS3: 5.5
nvd
больше 3 лет назад

An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.

EPSS

Процентиль: 31%
0.00119
Низкий

7.5 High

CVSS3

Дефекты

CWE-835