CVE-2020-8244
Summary
| CVE | CVE-2020-8244 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-30 15:15:00 UTC |
| Updated | 2022-05-24 17:31:00 UTC |
| Description | A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2698-1] node-bl security update |
MLIST |
lists.debian.org |
|
| HackerOne |
MISC |
hackerone.com |
Exploit, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178691 Debian Security Update for node-bl (DLA 2698-1)
- 198527 Ubuntu Security Notification for bl Vulnerability (USN-5098-1)
- 982627 Nodejs (npm) Security Update for bl (GHSA-pp7h-53gx-mx7r)