Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-21270

Опубликовано: 16 мая 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

A flaw was found in nodejs-stringstream. Node.js stringstream module is vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream.

Отчет

Red Hat Quay include stringstream as a dependency of Karma. Karma is only used at build time, and not at runtime reducing the impact of this vulnerability to low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 4kibanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopNot affected
Red Hat Quay 3quay/quay-rhel8FixedRHSA-2021:391719.10.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1927293nodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure

EPSS

Процентиль: 57%
0.0036
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
nvd
больше 4 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
debian
больше 4 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulner ...

github
почти 6 лет назад

Out-of-bounds Read in stringstream

EPSS

Процентиль: 57%
0.0036
Низкий

6.5 Medium

CVSS3