Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16026

Опубликовано: 16 нояб. 2015
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Request is an http client. If a request is made using multipart, and the body type is a number, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs-requestWill not fix
Red Hat Mobile Application Platform 4nodejs-requestNot affected
Red Hat OpenShift Enterprise 3nodejs-requestNot affected
Red Hat Software Collectionsrh-nodejs6-nodejs-requestNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1588833nodejs-request: Remote Memory Exposure when a multipart request is made

EPSS

Процентиль: 73%
0.00774
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.

CVSS3: 5.9
nvd
больше 7 лет назад

Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.

CVSS3: 5.9
debian
больше 7 лет назад

Request is an http client. If a request is made using ```multipart```, ...

CVSS3: 5.9
github
около 7 лет назад

Remote Memory Exposure in request

EPSS

Процентиль: 73%
0.00774
Низкий

4.3 Medium

CVSS3