CVE-2021-23386
Summary
| CVE | CVE-2021-23386 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-20 17:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Remote Memory Exposure in dns-packet | Snyk |
MISC |
snyk.io |
|
| Remote Memory Exposure in org.webjars.npm:dns-packet | Snyk |
MISC |
snyk.io |
|
| do trim on encodingLength as well · mafintosh/dns-packet@25f15dd · GitHub |
MISC |
github.com |
|
| HackerOne |
MISC |
hackerone.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: chalker
Legacy QID Mappings
- 982382 Nodejs (npm) Security Update for dns-packet (GHSA-3wcq-x3mq-6r9p)