Bufferlist Project Bufferlist 4.0.2 for Node.js

CPE Details

Bufferlist Project Bufferlist 4.0.2 for Node.js
4.0.2
2020-11-03
17h56 +00:00
2020-11-03
17h56 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:bufferlist_project:bufferlist:4.0.2:*:*:*:*:node.js:*:*

Informations

Vendor

bufferlist_project

Product

bufferlist

Version

4.0.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-8244 2020-08-30 11h43 +00:00 A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
6.5
Moyen