QID 982904
QID 982904: Nodejs (npm) Security Update for stringstream (GHSA-mf6x-7mm4-x2g7)
All versions of `stringstream` are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below.
## Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module if user input is being passed in to `stringstream`.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mf6x-7mm4-x2g7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mf6x-7mm4-x2g7 -
github.com/advisories/GHSA-mf6x-7mm4-x2g7
CVEs related to QID 982904
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mf6x-7mm4-x2g7 | stringstream |
|