PT-2018-16185 · Memjs · Memjs

Chalker

·

Publicado

2018-07-05

·

Atualizado

2019-10-09

·

CVE-2018-3767

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions memjs versions <= 1.1.0 memjs versions prior to 1.2.2
Description The issue results in Denial of Service (DoS) and uninitialized memory usage due to the allocation and storage of buffers on typed input. The package fails to sanitize the value option passed to the Buffer constructor, allowing attackers to pass large values that exhaust system resources.
Recommendations For memjs versions <= 1.1.0, upgrade to version 1.2.2 or later. For memjs versions prior to 1.2.2, upgrade to version 1.2.2 or later.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3767
GHSA-CX8M-8XMX-Q8V3

Produtos afetados

Memjs