CVE-2017-15897
Summary
| CVE | CVE-2017-15897 |
|---|---|
| State | PUBLISHED |
| Assigner | nodejs |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-11 21:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases. |
Risk And Classification
Primary CVSS: v3.1 3.1 LOW from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.006420000 probability, percentile 0.708550000 (date 2026-05-17)
Problem Types: CWE-665 | Un-initialized Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 3.1 | LOW | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | The Node.js Project | Node.js | affected 8.0 and higher | Not specified |
| CNA | The Node.js Project | Node.js | affected 9.0 and higher | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Data Confidentiality/Integrity Vulnerability, December 2017 | Node.js | af854a3a-2127-422b-91ae-364da2661108 | nodejs.org | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.