Описание
detect-character-encoding is an open source character encoding inspection library. In detect-character-encoding v0.6.0 and earlier, data matching no charset causes the Node.js process to crash. The problem has been patched in detect-character-encoding v0.7.0. No workaround are available and all users should update to resolve this issue.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.0 (исключая)
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 67%
0.00528
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-755
CWE-755
Связанные уязвимости
CVSS3: 7.5
github
больше 4 лет назад
Improper Handling of Exceptional Conditions in detect-character-encoding
EPSS
Процентиль: 67%
0.00528
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-755
CWE-755