PT-2020-4060 · Node.Js+8 · Node.Js+8

Published

2020-01-24

·

Updated

2026-05-18

·

CVE-2020-8174

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Node.js versions prior to 10.21.0 Node.js versions prior to 12.18.0 Node.js versions prior to 14.4.0
Description: The issue is related to memory corruption in the napi get value string *() functions, specifically napi get value string latin1(), napi get value string utf8(), and napi get value string utf16(), which can lead to buffer overflow. This can allow a remote attacker to execute arbitrary code.
Recommendations: For Node.js versions prior to 10.21.0, update to version 10.21.0 or later. For Node.js versions prior to 12.18.0, update to version 12.18.0 or later. For Node.js versions prior to 14.4.0, update to version 14.4.0 or later.

Exploit

Fix

Buffer Overflow

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:2848
ALSA-2020:2852
ALT-PU-2020-1090
ALT-PU-2020-2223
ALT-PU-2020-2926
ALT-PU-2022-3073
BDU:2020-04460
BDU:2020-05054
BIT-NODE-2020-8174
BIT-NODE-MIN-2020-8174
CESA-2020_2848
CESA-2020_2852
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2020-8174
DSA-4696-1
MGASA-2020-0372
OPENSUSE-SU-2020:0802-1
OPENSUSE-SU-2020_0802-1
OPENSUSE-SU-2024:11096-1
RHSA-2020:2847
RHSA-2020:2848
RHSA-2020:2849
RHSA-2020:2852
RHSA-2020:2895
RHSA-2020:3042
RHSA-2020:3084
RHSA-2020_2848
RHSA-2020_2852
RLSA-2020:2848
RLSA-2020:2852
SUSE-SU-2020:1568-1
SUSE-SU-2020:1575-1
SUSE-SU-2020:1576-1
SUSE-SU-2020:1606-1
SUSE-SU-2020:1623-1
SUSE-SU-2020:2800-1
SUSE-SU-2020_1568-1
SUSE-SU-2020_1575-1
SUSE-SU-2020_1576-1
SUSE-SU-2020_1606-1
SUSE-SU-2020_1623-1
USN-6380-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu