[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2024-2410 --- libuv

ID: oval:org.secpod.oval:def:1702042Date: (C)2024-02-07   (M)2024-02-07
Class: PATCHFamily: unix




Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo

Platform:
Amazon Linux 2
Product:
libuv
Reference:
ALAS2-2024-2410
CVE-2021-22918
CVE    1
CVE-2021-22918
CPE    2
cpe:/a:libuv:libuv
cpe:/o:amazon:linux:2

© SecPod Technologies