Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
2021-07-12T11:15:07.937
2024-11-21T05:50:54.763
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | < 12.22.2 | Yes |
Application | nodejs | node.js | < 14.17.2 | Yes |
Application | nodejs | node.js | < 16.4.1 | Yes |
Application | siemens | sinec_infrastructure_network_services | < 1.0.1.1 | Yes |