Bufferlist Project Bufferlist 1.2.2 for Node.js

CPE Details

Bufferlist Project Bufferlist 1.2.2 for Node.js
1.2.2
2020-11-03
17h56 +00:00
2020-11-03
17h56 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:bufferlist_project:bufferlist:1.2.2:*:*:*:*:node.js:*:*

Informations

Vendor

bufferlist_project

Product

bufferlist

Version

1.2.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-8244 2020-08-30 11h43 +00:00 A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
6.5
Medium