Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
BID:70105
Info
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 70105 |
| Class: | Design Error |
| CVE: |
CVE-2014-7192 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2014 12:00AM |
| Updated: | Dec 09 2014 12:59AM |
| Credit: | Cal Leeming |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
syntax-error module for Node.js is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
Versions prior to syntax-error 1.1.1 are vulnerable.
syntax-error module for Node.js is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
Versions prior to syntax-error 1.1.1 are vulnerable.
Exploit / POC
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability
References:
References:
- Node.js Homepage (Joyent)