Описание
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.1.5+~3.1.2-1 |
| esm-apps/bionic | released | 3.0.14-2ubuntu0.1~esm1 |
| esm-apps/focal | released | 3.0.16-1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 3.1.2-2ubuntu0.1~esm1 |
| esm-apps/noble | released | 3.1.2-3ubuntu0.1~esm1 |
| esm-apps/resolute | not-affected | 3.1.5+~3.1.2-1 |
| jammy | needed | |
| noble | needed | |
| oracular | ignored | end of life, was needs-triage |
| plucky | ignored | end of life, was needs-triage |
Показывать по
Ссылки на источники
EPSS
Связанные уязвимости
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
Improper Input Validation vulnerability in pbkdf2 allows Signature Spo ...
pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos
Уязвимость библиотеки pbkdf2 программной платформы Node.js, позволяющая нарушителю подделать цифровую подпись
EPSS