You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
All versions of stringstream are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below.
Vulnerable Library - stringstream-0.0.1.tgz
Encode and decode streams into string streams
Library home page: https://registry.npmjs.org/stringstream/-/stringstream-0.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/stringstream/package.json
Found in HEAD commit: dccd6c209a19b6ae01e03508053a3841c0f47a29
Vulnerabilities
Details
CVE-2018-21270
Vulnerable Library - stringstream-0.0.1.tgz
Encode and decode streams into string streams
Library home page: https://registry.npmjs.org/stringstream/-/stringstream-0.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/stringstream/package.json
Dependency Hierarchy:
Found in HEAD commit: dccd6c209a19b6ae01e03508053a3841c0f47a29
Found in base branch: main
Vulnerability Details
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
Publish Date: 2020-12-03
URL: CVE-2018-21270
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21270
Release Date: 2020-12-03
Fix Resolution: 0.0.6
⛑️ Automatic Remediation is available for this issue
WS-2018-0103
Vulnerable Library - stringstream-0.0.1.tgz
Encode and decode streams into string streams
Library home page: https://registry.npmjs.org/stringstream/-/stringstream-0.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/stringstream/package.json
Dependency Hierarchy:
Found in HEAD commit: dccd6c209a19b6ae01e03508053a3841c0f47a29
Found in base branch: main
Vulnerability Details
All versions of stringstream are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below.
Publish Date: 2018-05-16
URL: WS-2018-0103
CVSS 3 Score Details (4.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/664
Release Date: 2018-01-27
Fix Resolution: 0.0.6
⛑️ Automatic Remediation is available for this issue
⛑️ Automatic Remediation is available for this issue.
The text was updated successfully, but these errors were encountered: