PT-2019-10483 · Node.Js · Stringstream

Chalker

·

Published

2019-06-20

·

Updated

2022-01-06

·

CVE-2018-21270

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Node.js stringstream module versions less than 0.0.6
Description The issue arises from the allocation of uninitialized buffers when a number is passed in the input stream, leading to an out-of-bounds read. This occurs when using Node.js 4.x.
Recommendations For versions less than 0.0.6, consider not installing or using this module if user input is being passed in to stringstream as a temporary workaround until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21270
GHSA-MF6X-7MM4-X2G7
GHSA-QPW2-XCHM-655Q

Affected Products

Stringstream