PT-2017-4098 · Microsoft · Uglify-Js
Publicado
2017-01-23
·
Atualizado
2021-05-25
·
CVE-2015-8858
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
uglify-js versions prior to 2.6.0
Description
The issue allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, also known as a "regular expression denial of service (ReDoS)". This can be exploited by passing malicious inputs into the
parse() method, leading to uncontrolled resource consumption. A remote attacker can use a specially crafted regular expression to achieve a denial of service.Recommendations
Update to version 2.6.0 or later. As a temporary workaround, consider restricting the use of the
parse() method until a patch is available. Avoid using the parse() method with untrusted input to minimize the risk of exploitation.Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Uglify-Js