PT-2014-6370 · Node.Js+1 · Node.Js+1

Published

2014-09-05

·

Updated

2016-02-10

·

CVE-2014-5256

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Node.js versions 0.8.0 through 0.8.27 Node.js versions 0.10.0 through 0.10.29
Description The issue allows remote attackers to cause a denial of service, resulting in memory corruption and application crash, via deep JSON objects. This occurs when the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt is not considered.
Recommendations For Node.js versions 0.8.0 through 0.8.27, update to version 0.8.28 or later. For Node.js versions 0.10.0 through 0.10.29, update to version 0.10.30 or later.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1086
CVE-2014-5256
MGASA-2014-0516
RHSA-2014:1744

Affected Products

Alt Linux
Node.Js