Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-36313

Опубликовано: 21 июл. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.

A flaw was found in the file-type npm package. A malformed MKV file could lead the file type detector to a denial of Service. This issue allows an attacker to input a malicious file and make the server unresponsive.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorAffected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Affected
Red Hat build of Apicurio Registry 2file-typeNot affected
Red Hat Integration Camel K 1file-typeWill not fix
Red Hat OpenShift Dev Spacesdevspaces/code-rhel8Affected
Red Hat OpenShift Dev Spacesdevspaces/idea-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2159682file-type: a malformed MKV file could cause the file type detector to get caught in an infinite loop

EPSS

Процентиль: 31%
0.00119
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.

CVSS3: 7.5
github
больше 3 лет назад

file-type vulnerable to Infinite Loop via malformed MKV file

EPSS

Процентиль: 31%
0.00119
Низкий

5.5 Medium

CVSS3