Описание
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
A flaw was found in nodejs. Calling napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() with a non-NULL buf, and a bufsize of 0 will cause the entire string value to be written to buf, probably overrunning the length of the buffer.
Отчет
NodeJS is a build time dependency of Red Hat Quay and is not used at runtime. Therefore this issue will not fixed in Quay 3.3.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | ||
Red Hat Quay 3 | nodejs | Will not fix | ||
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2020:2848 | 07.07.2020 |
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2020:2852 | 07.07.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs | Fixed | RHSA-2020:3042 | 21.07.2020 |
Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs | Fixed | RHSA-2020:2847 | 07.07.2020 |
Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs | Fixed | RHSA-2020:2849 | 07.07.2020 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs | Fixed | RHSA-2020:2895 | 13.07.2020 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs | Fixed | RHSA-2020:3084 | 21.07.2020 |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs | Fixed | RHSA-2020:2895 | 13.07.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
napi_get_value_string_*() allows various kinds of memory corruption in ...
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
EPSS
8.1 High
CVSS3