QID 982627
QID 982627: Nodejs (npm) Security Update for bl (GHSA-pp7h-53gx-mx7r)
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pp7h-53gx-mx7r for updates pertaining to this vulnerability.
Vendor References
- GHSA-pp7h-53gx-mx7r -
github.com/advisories/GHSA-pp7h-53gx-mx7r
CVEs related to QID 982627
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pp7h-53gx-mx7r | bl |
|