CVE-2022-25345
Summary
| CVE | CVE-2022-25345 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-17 20:15:00 UTC |
| Updated | 2022-06-28 12:57:00 UTC |
| Description | All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash. |
Risk And Classification
Problem Types: CWE-908
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Denial of Service (DoS) in @discordjs/opus | CVE-2022-25345 | Snyk | CONFIRM | snyk.io | |
| N/A | CONFIRM | github.com | |
| opus/node-opus.cc at 3ca4341ffdd81cf83cec57045e59e228e6017590 · discordjs/opus · GitHub | MITRE | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Cristian-Alexandru Staicu
Legacy QID Mappings
- 902360 Common Base Linux Mariner (CBL-Mariner) Security Update for opus (9959)