PT-2018-16185 · Memjs · Memjs
Chalker
·
Publicado
2018-07-05
·
Atualizado
2019-10-09
·
CVE-2018-3767
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
memjs versions <= 1.1.0
memjs versions prior to 1.2.2
Description
The issue results in Denial of Service (DoS) and uninitialized memory usage due to the allocation and storage of buffers on typed input. The package fails to sanitize the
value option passed to the Buffer constructor, allowing attackers to pass large values that exhaust system resources.Recommendations
For memjs versions <= 1.1.0, upgrade to version 1.2.2 or later.
For memjs versions prior to 1.2.2, upgrade to version 1.2.2 or later.
Exploit
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Memjs