PT-2017-7489 · Npm+2 · Semver+2

Published

2016-04-13

·

Updated

2021-03-15

·

CVE-2015-8855

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions semver versions prior to 4.3.2
Description The issue allows attackers to cause a denial of service, specifically CPU consumption, via a long version string. This is referred to as a regular expression denial of service (ReDoS). The vulnerability is triggered when extremely long version strings are parsed.
Recommendations Update to version 4.3.2 or later. As a temporary workaround, consider restricting the input of version strings to prevent extremely long strings from being parsed.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1328
CVE-2015-8855
GHSA-X6FG-F45M-JF5Q
USN-4776-1

Affected Products

Alt Linux
Ubuntu
Semver