Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7191

Опубликовано: 06 авг. 2014
Источник: redhat
CVSS2: 4.3

Описание

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

The nodejs-qs module has the ability to create sparse arrays during parsing. By specifying a high index in a querystring parameter it is possible to create a large array that will eventually take up all the allocated memory of the running process, resulting in a crash.

Отчет

This package is not shipped with any versions of Red Hat Enterprise Linux. Red Hat Software Collections Library components shipping in version 2.2 are affected.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1146054nodejs-qs: Denial-of-Service Memory Exhaustion

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

nvd
почти 11 лет назад

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

debian
почти 11 лет назад

The qs module before 1.0.0 in Node.js does not call the compact functi ...

github
почти 8 лет назад

Denial-of-Service Memory Exhaustion in qs

4.3 Medium

CVSS2