PT-2018-4721 · Ws · Ws

Alchemystic

·

Published

2018-05-31

·

Updated

2019-10-09

·

CVE-2016-10542

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ws versions 1.1.0 and earlier
Description The issue allows an attacker to crash the node process by sending an overly long websocket payload to a ws server. This is due to the affected versions of ws not appropriately limiting the size of incoming websocket payloads, resulting in a denial of service condition.
Recommendations Update to version 1.1.1 or later. Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

Fix

RCE

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10542
GHSA-6663-C963-2GQG

Affected Products

Ws