Description
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0549 | Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x). |
Github GHSA |
GHSA-mf6x-7mm4-x2g7 | Out-of-bounds Read in stringstream |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:26:39.596Z
Reserved: 2020-12-03T00:00:00.000Z
Link: CVE-2018-21270
No data.
Status : Modified
Published: 2020-12-03T21:15:11.100
Modified: 2024-11-21T04:03:19.940
Link: CVE-2018-21270
OpenCVE Enrichment
No data.
EUVD
Github GHSA