PT-2018-4721 · Ws · Ws

Alchemystic

·

Publicado

2018-05-31

·

Atualizado

2019-10-09

·

CVE-2016-10542

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ws versions 1.1.0 and earlier
Description The issue allows an attacker to crash the node process by sending an overly long websocket payload to a ws server. This is due to the affected versions of ws not appropriately limiting the size of incoming websocket payloads, resulting in a denial of service condition.
Recommendations Update to version 1.1.1 or later. Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

Correção

RCE

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10542
GHSA-6663-C963-2GQG

Produtos afetados

Ws