PT-2017-7489 · Npm+2 · Semver+2

Publicado

2016-04-13

·

Atualizado

2021-03-15

·

CVE-2015-8855

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions semver versions prior to 4.3.2
Description The issue allows attackers to cause a denial of service, specifically CPU consumption, via a long version string. This is referred to as a regular expression denial of service (ReDoS). The vulnerability is triggered when extremely long version strings are parsed.
Recommendations Update to version 4.3.2 or later. As a temporary workaround, consider restricting the input of version strings to prevent extremely long strings from being parsed.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1328
CVE-2015-8855
GHSA-X6FG-F45M-JF5Q
USN-4776-1

Produtos afetados

Alt Linux
Ubuntu
Semver