PT-2018-3672 · Debug · Debug

Publicado

2018-06-07

·

Atualizado

2021-05-25

·

CVE-2017-16137

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions debug versions prior to 2.6.9 debug versions 3.2.0 through 3.2.6 debug versions 4.0.0 through 4.3.0
Description The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. This issue is considered low severity as it takes around 50,000 characters to block the event loop for 2 seconds. The vulnerability can be exploited by a remote attacker using a specially crafted regular expression, potentially leading to a denial of service.
Recommendations Version 2.x.x: Update to version 2.6.9 or later. Version 3.1.x: Update to version 3.1.0 or later. Version 3.2.x: Update to version 3.2.7 or later. Version 4.x.x: Update to version 4.3.1 or later.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-43792
AZL-43819
AZL-44400
AZL-44772
BDU:2021-02886
CVE-2017-16137
GHSA-GXPJ-CX7G-858C

Produtos afetados

Debug