UNKNOWN npm
Denial-of-Service Memory Exhaustion in qs
GHSA-jjv7-qpx3-h62q · CVE-2014-7191
Published · Modified
Description
Versions prior to 1.0 of qs are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing.
Recommendation
Update to version 1.0.0 or later.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2014-7191
- WEB https://github.com/visionmedia/node-querystring/issues/104
- WEB https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8
- WEB https://access.redhat.com/errata/RHSA-2016:1380
- WEB https://exchange.xforce.ibmcloud.com/vulnerabilities/96729
- ADVISORY https://github.com/advisories/GHSA-jjv7-qpx3-h62q
- PACKAGE https://github.com/visionmedia/node-querystring
- WEB https://www.npmjs.com/advisories/29
- WEB http://secunia.com/advisories/60026
- WEB http://secunia.com/advisories/62170
- WEB http://www-01.ibm.com/support/docview.wss?uid=swg21685987
- WEB http://www-01.ibm.com/support/docview.wss?uid=swg21687263
- WEB http://www-01.ibm.com/support/docview.wss?uid=swg21687928
Ready to move
Start Securing
Free, no credit card | First findings in minutes