Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3cj-3539-rcpx

Опубликовано: 13 июл. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Out-of-Bounds Read in Node.js

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

EPSS

Процентиль: 72%
0.00743
Низкий

8.2 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

CVSS3: 5.3
redhat
почти 4 года назад

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

CVSS3: 5.3
nvd
почти 4 года назад

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

CVSS3: 5.3
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
почти 4 года назад

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bou ...

EPSS

Процентиль: 72%
0.00743
Низкий

8.2 High

CVSS3

Дефекты

CWE-125