Description
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18906 | Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour. |
References
History
No history.
Status: PUBLISHED
Assigner: nodejs
Published:
Updated: 2024-09-17T00:56:13.228Z
Reserved: 2018-02-15T00:00:00.000Z
Link: CVE-2018-7164
No data.
Status : Modified
Published: 2018-06-13T16:29:01.827
Modified: 2024-11-21T04:11:42.403
Link: CVE-2018-7164
OpenCVE Enrichment
No data.
Weaknesses
EUVD