Node.js dns-sync Library Arbitrary Command Execution Vulnerability
BID:71054
Info
Node.js dns-sync Library Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 71054 |
| Class: | Design Error |
| CVE: |
CVE-2014-9682 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2014 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Steve Kemp |
| Vulnerable: |
Skoranga dns-sync 0.1 |
| Not Vulnerable: | |
Discussion
Node.js dns-sync Library Arbitrary Command Execution Vulnerability
dns-sync library for Node.js is prone to a vulnerability that lets attackers execute arbitrary commands.
Attackers can exploit this vulnerability to execute arbitrary commands in the context of the affected application.
Versions prior to dns-sync 0.1.1 are vulnerable.
dns-sync library for Node.js is prone to a vulnerability that lets attackers execute arbitrary commands.
Attackers can exploit this vulnerability to execute arbitrary commands in the context of the affected application.
Versions prior to dns-sync 0.1.1 are vulnerable.
Exploit / POC
Node.js dns-sync Library Arbitrary Command Execution Vulnerability
An attacker can exploit this issue using readily available commands and tools.
An attacker can exploit this issue using readily available commands and tools.
Solution / Fix
Node.js dns-sync Library Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Node.js dns-sync Library Arbitrary Command Execution Vulnerability
References:
References:
- adding validation check for hostname (Skoranga)
- dns-sync Homepage (Node.js)
- Node.js Homepage (Joyent)
- This package contains a serious security hole. #1 (Skoranga)