Описание
ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than Buffer causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a Buffer using Buffer.isBuffer(obj).
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ced_project:ced:0.1.0:*:*:*:*:node.js:*:*
EPSS
Процентиль: 63%
0.00446
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-241
CWE-755
Связанные уязвимости
CVSS3: 7.5
github
около 4 лет назад
Improper Handling of Unexpected Data Type in ced
EPSS
Процентиль: 63%
0.00446
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-241
CWE-755