QID 982885
QID 982885: Nodejs (npm) Security Update for printf (GHSA-xfhp-gmh8-r8v2)
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xfhp-gmh8-r8v2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-xfhp-gmh8-r8v2 -
github.com/advisories/GHSA-xfhp-gmh8-r8v2
CVEs related to QID 982885
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xfhp-gmh8-r8v2 | printf |
|