CVE-2018-7167

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.25 % (65th)
0.25% Progress
Affected Products 1
Advisories 9

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Node.js
Published Date
2018-06-13 16:29:01
(6 years ago)
Updated Date
2022-08-29 20:24:33
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Nodejs Node.js above 6.9.0 version and prior 6.14.3 version cpe:2.3:a:nodejs:node.js::*:*:*:lts > 6.9.0 < 6.14.3
  Nodejs Node.js from 8.9.0 version and prior 8.11.3 version cpe:2.3:a:nodejs:node.js::*:*:*:lts >= 8.9.0 < 8.11.3
  Nodejs Node.js from 9.0.0 version and prior 9.11.2 version cpe:2.3:a:nodejs:node.js::*:*:*:- >= 9.0.0 < 9.11.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...