PT-2018-4699 · Node.Js · Bittorrent-Dht

Feross

·

Published

2018-05-31

·

Updated

2020-09-01

·

CVE-2016-10519

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions bittorrent-dht versions prior to 5.1.3
Description A security issue in bittorrent-dht allows an attacker to send a specific series of messages to a listening peer, causing it to reveal internal memory. This remote memory disclosure vulnerability is mitigated by two factors: modern kernels zeroing out new memory pages before allocation, and Node.js managing Buffers in a way that only previously allocated Buffer memory can be leaked.
Recommendations Update to version 5.1.3 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10519
GHSA-77G4-36JP-5V3M

Affected Products

Bittorrent-Dht