PT-2018-4699 · Node.Js · Bittorrent-Dht
Feross
·
Published
2018-05-31
·
Updated
2020-09-01
·
CVE-2016-10519
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
bittorrent-dht versions prior to 5.1.3
Description
A security issue in bittorrent-dht allows an attacker to send a specific series of messages to a listening peer, causing it to reveal internal memory. This remote memory disclosure vulnerability is mitigated by two factors: modern kernels zeroing out new memory pages before allocation, and Node.js managing Buffers in a way that only previously allocated Buffer memory can be leaked.
Recommendations
Update to version 5.1.3 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bittorrent-Dht